| CVE ID | CVE-2026-15390 |
| Publication date | 29 September 2026 |
| Vendor | DENX Software Engineering |
| Product | Das U-Boot |
| Vulnerable versions | From 2009.08 through 2026.07 |
| Vulnerability type (CWE) | Out-of-bounds write (CWE-787) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in DENX Software Engineering Das U-Boot software and participated in coordination of its disclosure.
The vulnerability CVE-2026-15390: Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa included in release version 2026.07.
Credits
We thank Mateusz Furdyna from Nokia for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.