{"id":"CVE-2026-71973","published":"2026-09-29T22:18:22.080","lastModified":"2026-09-29T22:18:22.080","description":"U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.","cvssScore":5.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","cwes":["CWE-190"],"vendors":[],"products":[],"references":[{"url":"https://github.com/u-boot/u-boot","tags":[]},{"url":"https://github.com/u-boot/u-boot/blob/v2026.07/fs/squashfs/sqfs.c#L814","tags":[]},{"url":"https://github.com/u-boot/u-boot/commit/561ae28cb56a082cfa90c1c421c4955bc215470b","tags":[]},{"url":"https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc4-integer-overflow-in-squashfs-directory-table-allocation","tags":[]}],"exploitRefs":[{"url":"https://github.com/u-boot/u-boot","tags":[]},{"url":"https://github.com/u-boot/u-boot/blob/v2026.07/fs/squashfs/sqfs.c#L814","tags":[]},{"url":"https://github.com/u-boot/u-boot/commit/561ae28cb56a082cfa90c1c421c4955bc215470b","tags":[]}],"hasPoc":true,"ai":null}