---
id: CVE-2026-74225
title: >-
  U-Boot before 2026.10-rc5 contains out-of-bounds memory access in
  dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option
  lengths from DHCPv6 packets
summary: >-
  U-Boot before 2026.10-rc5 contains out-of-bounds memory access in
  dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option
  lengths from DHCPv6 packets. Attackers on the local network can send crafted
  DHCPv6 ADVERTISE or …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-787
vendor: u-boot
product: u-boot
affected:
  - u-boot < 2026.10-rc5
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T22:18:33.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74225'
references:
  - url: 'https://github.com/u-boot/u-boot'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/u-boot/u-boot/blob/v2026.07/net/dhcpv6.c#L304'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/u-boot/u-boot/commit/20209a62bc8565fc1e040882bc03c71ff0d73076
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-out-of-bounds-write-via-dhcpv6
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T21:49:08.266Z'
---

## Overview

U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
