U-Boot · U-Boot · CVE-2026-15390
**Name of the Vulnerable Software and Affected Versions**
U-Boot versions prior to 2026.07
**Description**
When configured with the `CONFIG IP DEFRAG=y` parameter, the software fails to clear the IP reassembly state after delivering a complete datagram. This allows an attacker capable of delivering fragmented IP traffic to execute arbitrary code by sending duplicated last-fragment IP packets.
**Recommendations**
Update to version 2026.07.
As a temporary mitigation, disable the `CONFIG IP DEFRAG=y` configuration parameter.