Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8884-1: U-Boot vulnerabilities

Multiple security vulnerabilities were found in the U-Boot boot loader used by Ubuntu. These flaws involve improper handling of malformed ZFS and ext4 file system metadata, as well as incorrect processing of fragmented IP traffic with defragmentation enabled. An attacker could exploit these issues to run unauthorized code or cause a denial of service, potentially disrupting device startup or operation.

QCS published 7/10/2026, 1:44:52 am ISTVendor disclosure 6/10/2026, 9:39:02 pm ISTVerified 7/10/2026, 1:44:52 am ISTRevision 1

In plain language

What this advisory means

Multiple security vulnerabilities were found in the U-Boot boot loader used by Ubuntu. These flaws involve improper handling of malformed ZFS and ext4 file system metadata, as well as incorrect processing of fragmented IP traffic with defragmentation enabled. An attacker could exploit these issues to run unauthorized code or cause a denial of service, potentially disrupting device startup or operation.

Technical explanation

How the issue affects the environment

U-Boot has several vulnerabilities identified by researchers: (1) improper handling of malformed ZFS metadata leading to integer overflow and out-of-bounds memory access (CVE-2025-70290); (2) incorrect calculation of buffer sizes when processing ext4 file systems, causing similar risks (CVE-2025-70293); (3) flawed processing of fragmented IP traffic when IP defragmentation is active, which may corrupt memory (CVE-2026-15390); and (4) mishandling of fragmented IP traffic during network boot with defragmentation enabled, which can cause out-of-bounds memory writes and potential denial of service (CVE-2026-71971). These issues could be exploited to execute arbitrary code or disrupt system operation during booting.

Operational impact

Why teams should care

If exploited, these vulnerabilities could allow attackers to compromise the boot process on affected Ubuntu systems, potentially leading to device control takeover or service outages. This poses risks to mission-critical systems relying on embedded devices or servers using U-Boot for bootstrapping, impacting availability and security of services.

Immediate action

The vulnerabilities are addressed by installing updated U-Boot packages provided by Ubuntu for each supported release. Systems should apply the security updates via the official package management tools to replace vulnerable U-Boot components with patched versions.

Affected and fixed releases

Affected versionsUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 26.04 LTS
Fixed versionsUbuntu 18.04 LTS: u-boot packages updated for Ubuntu Pro, Ubuntu 20.04 LTS: u-boot packages updated for Ubuntu Pro, Ubuntu 22.04 LTS: u-boot package versions 2022.01+dfsg-2ubuntu2.8, Ubuntu 24.04 LTS: u-boot package versions 2025.10-0ubuntu0.24.04.3, Ubuntu 26.04 LTS: u-boot package versions 2025.10-0ubuntu2.1

Temporary risk reduction

The advisory does not specify any workaround measures. Mitigation requires applying updates that correct the underlying code flaws in U-Boot.

Evidence and validation checklist

  • Official Ubuntu Security Notice USN-8884-1
  • Identified CVEs: CVE-2025-70290, CVE-2025-70293, CVE-2026-15390, CVE-2026-71971
  • Package version updates listed for each Ubuntu release
  • Researcher-discovered incorrect handling of file system metadata and fragmented IP traffic

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source