{"id":"CVE-2026-15390","published":"2026-09-29T10:17:11.237","lastModified":"2026-09-29T11:16:42.610","description":"Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.\n\n\nThis issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-459","CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://cert.pl/en/posts/2026/09/CVE-2026-15390","tags":[]},{"url":"https://source.denx.de/u-boot/u-boot/-/commit/b1aec609bb5e0d08c25c888c91935287ab4ee5fa","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}