---
id: CVE-2026-71974
title: >-
  U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in
  read_slotted_partition() that fails to validate image size against partition
  bounds
summary: >-
  U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in
  read_slotted_partition() that fails to validate image size against partition
  bounds. Attackers with physical access can supply crafted boot media with
  oversized h…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-787
vendor: u-boot
product: u-boot
affected:
  - u-boot < 2026.10-rc3
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T22:18:22.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71974'
references:
  - url: 'https://github.com/u-boot/u-boot'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/u-boot/u-boot/blob/v2026.07/boot/bootmeth_android.c#L356
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76
    label: disclosure@vulncheck.com
  - url: >-
      https://patch.msgid.link/20260729-b4-android-bootmeth-oob-v1-1-31c3450ae0be@byteray.co.uk
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-via-android-bootmeth-partition-read
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T21:49:08.268Z'
---

## Overview

U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
