Home / mailingsPDF  

[USN-8884-1] U-Boot vulnerabilities

Posted on 06 October 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8884-1
October 06, 2026

u-boot vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in U-Boot.

Software Description:
- u-boot: A boot loader for embedded systems

Details:

Timo Preißl discovered that U-Boot incorrectly handled certain malformed
ZFS file system metadata. An attacker could possibly use this issue to
trigger an integer overflow and out-of-bounds memory access, resulting in
arbitrary code execution or a denial of service. (CVE-2025-70290)

Timo Preißl discovered that U-Boot incorrectly calculated buffer sizes when
processing certain ext4 file systems. An attacker could possibly use this
issue to trigger an integer overflow and out-of-bounds memory access,
resulting in arbitrary code execution or a denial of service. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2025-70293)

Mateusz Furdyna discovered that U-Boot incorrectly handled certain
fragmented IP traffic when IP defragmentation was enabled. An attacker
could possibly use this issue to corrupt memory by sending crafted IP
fragments, resulting in arbitrary code execution. (CVE-2026-15390)

Shahriyar Jalayeri and Mehrun P. Hunter discovered that U-Boot incorrectly
handled certain fragmented IP traffic during network boot when IP
defragmentation was enabled. An attacker could possibly use this issue to
trigger an out-of-bounds write, resulting in a denial of service.
(CVE-2026-71971)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
u-boot-imx 2025.10-0ubuntu2.1
u-boot-qemu 2025.10-0ubuntu2.1
u-boot-tools 2025.10-0ubuntu2.1

Ubuntu 24.04 LTS
u-boot-imx 2025.10-0ubuntu0.24.04.3
u-boot-qemu 2025.10-0ubuntu0.24.04.3
u-boot-tools 2025.10-0ubuntu0.24.04.3

Ubuntu 22.04 LTS
u-boot-imx 2022.01+dfsg-2ubuntu2.8
u-boot-qemu 2022.01+dfsg-2ubuntu2.8
u-boot-tools 2022.01+dfsg-2ubuntu2.8

Ubuntu 20.04 LTS
u-boot-imx 2021.01+dfsg-3ubuntu0~20.04.6+esm1
Available with Ubuntu Pro
u-boot-qemu 2021.01+dfsg-3ubuntu0~20.04.6+esm1
Available with Ubuntu Pro
u-boot-tools 2021.01+dfsg-3ubuntu0~20.04.6+esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
u-boot-imx 2020.10+dfsg-1ubuntu0~18.04.3+esm1
Available with Ubuntu Pro
u-boot-qemu 2020.10+dfsg-1ubuntu0~18.04.3+esm1
Available with Ubuntu Pro
u-boot-tools 2020.10+dfsg-1ubuntu0~18.04.3+esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
u-boot-imx 2016.01+dfsg1-2ubuntu5+esm1
Available with Ubuntu Pro
u-boot-tools 2016.01+dfsg1-2ubuntu5+esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8884-1
CVE-2025-70290, CVE-2025-70293, CVE-2026-15390, CVE-2026-71971

Package Information:
https://launchpad.net/ubuntu/+source/u-boot/2025.10-0ubuntu2.1
https://launchpad.net/ubuntu/+source/u-boot/2025.10-0ubuntu0.24.04.3
https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.8

--===============3391726071182287146==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP