U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-195"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74220.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74220.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "128626427552653897243693517561781227734",
"length": 1295
},
"id": "CVE-2026-74220-5b51acf0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/u-boot/u-boot/commit/0bbf09859658b8cc9ac13be41af23b516b8ef69a",
"target": {
"file": "net/nfs-common.c",
"function": "nfs_read_reply"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"320793198180052761043446129304245412766",
"339626875598794819735382856224578102028",
"256778714225060571425110820085662760996",
"35698416915743218851232561443195284241",
"238807569870928325265407972714841281292",
"69654209686356862874948777599076594643",
"186164151011140158531701792698463556403",
"200693821633784765261967198889597850508",
"234749786293585380748935495222038920691",
"332145140071611066907260215046973334331",
"268448813373580851171452236127667946832",
"119601121266011010546904533141788938645"
],
"threshold": 0.9
},
"id": "CVE-2026-74220-fdbaba37",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/u-boot/u-boot/commit/0bbf09859658b8cc9ac13be41af23b516b8ef69a",
"target": {
"file": "net/nfs-common.c"
}
}
]
"2026-10-02T08:13:35Z"