CVE-2026-29007 | U-Boot up to 2026.04-rc3 TCP State Machine net/tcp.c tcp_parse_options data offset out-of-bounds
A vulnerability labeled as very critical has been found in U-Boot up to 2026.04-rc3. This vulnerability affects the function tcp_parse_options of the file net/tcp.c of the component TCP State Machine. Executing a manipulation of the argument data offset can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-29007. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More