Logo
vulnerabilityCVE-2026-29007
Name
CVE-2026-29007
Source
NVD ( link)Debian ( link)
Description
U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
u-boot
Exploitable

Vulnerability Ratings#


6.9
CVSSv4
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2021.07
Exploitable
buildroot
master
2026.07
Not Affected
yocto
kirkstone
2022.01
Exploitable
yocto
master
2026.07
Not Affected