Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mateusz Furdyna

Researcher fromNokia
#30508of 57,355
9Total CVSS
Vulnerabilities · 1
PT-2026-102493
9
2026-09-29
U-Boot · U-Boot · CVE-2026-15390
**Name of the Vulnerable Software and Affected Versions** U-Boot versions prior to 2026.07 **Description** When configured with the `CONFIG IP DEFRAG=y` parameter, the software fails to clear the IP reassembly state after delivering a complete datagram. This allows an attacker capable of delivering fragmented IP traffic to execute arbitrary code by sending duplicated last-fragment IP packets. **Recommendations** Update to version 2026.07. As a temporary mitigation, disable the `CONFIG IP DEFRAG=y` configuration parameter.