Post

Discovering My First CVEs in U-Boot — and the Long Wait for Glory

Discovering My First CVEs in U-Boot — and the Long Wait for Glory

Introduction

At the start of 2026 I read a heise report about vulnerabilities in the U-Boot bootloader that allowed bypassing the chain of trust. The write-up described a class of integer overflows.

A few days of grep, a lot of source reading. Eventually I found four more issues, all of the same shape, an integer overflow leading to an under-allocation, which in turn enables out-of-bounds reads/writes.

Why this pattern is dangerous

In application code an OOB write is bad. In a bootloader it is a different category of problem, because the bootloader runs before every trust boundary the system has.

Two concrete outcomes make this class worth taking seriously:

  • Bricking. A malformed structure processed at boot can crash the device on the next reboot — turning a remote or supply-chain triggerable bug into a permanent denial of service on hardware that may not be easy to re-flash.
  • Persistence below the OS. Combined with a kernel compromise, an attacker can manipulate the filesystem and re-establish control underneath the operating system on every boot. That is one of the key building blocks for durable IoT botnets.

And U-Boot sits underneath an enormous range of embedded products, so a single bug class here has a wide blast radius. The repository sits far upstream and bootloaders generally don’t get updated that often especially on IOT-Devices

The patches

For each issue I wrote a patch modeled on the fixes already accepted for the previously disclosed overflows, so the style and approach matched what the maintainers had already merged.

After a few review rounds with the U-Boot maintainers, the patches were merged into mainline. Details can be found here:

This is the part that matters most: the fixes are in the mainline tree today, and anyone can verify the commits.

Reporting the CVEs

U-Boot is not its own CNA, so I requested CVE IDs from MITRE. The IDs are assigned and the vulnerabilities are fully documented through the merged fixes and my public reports; the complete CVE records are still working their way through publication.

My full reports and links to the fixes:

uboot

Conclusion

Following the current evolution of AI and seeing mythos sweep away thousand of bugs, this kind of hunt will probably be highly automated soon. Nonetheless i am still proud to have done a full cycle of variant analysis the old fashioned way from analyzing the pattern, to grepping and finally fixing and merging.

Thx for reading :)

This post is licensed under CC BY 4.0 by the author.