CVE Tools

U-boot

48 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for U-boot, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

U-boot CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
U-boot CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-026
2025-030
2025-040
2025-050
2025-060
2025-070
2025-081
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-051
2026-060
2026-073
2026-080
2026-090

Severity

How the 48 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1838%
  • High2246%
  • Medium715%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting U-boot.

  1. CVE-2026-29009U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK8.2
  2. CVE-2026-29008U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()7.5
  3. CVE-2026-29007U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c5.3
  4. CVE-2026-46728Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.8.2
  5. CVE-2025-24857Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ957...7.6
  6. CVE-2025-45512A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.6.5
  7. CVE-2024-57258Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.7.1
  8. CVE-2024-57254An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem.7.1
  9. CVE-2024-57257A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.2.0
  10. CVE-2024-57255An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant m...7.1
  11. CVE-2024-57259sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a s...7.1
  12. CVE-2024-57256An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, result...7.1
  13. CVE-2022-2347Unchecked Download size in Uboot7.7
  14. CVE-2022-33967squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading ...7.8
  15. CVE-2022-33103Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store