Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)

News

When analysing firmware attack surfaces, image decoders built into bootloaders get less scrutiny than cryptographically verified OS kernels. If image parsing happens before signature verification, any memory corruption in the parser breaks the secure boot trust model. researchers analysed U-Boot’s video subsystem (drivers/video/video_bmp.c) and identified an unbounded write in the RLE8 bitmap decoder (video_display_rle8_bitmap()) that leads to a pre-authentication Secure Boot bypass. Root Cause and Vulnerability Mechanics When U-Boot displays a boot logo or splash screen, it parses a BMP image loaded from local storage (SPI flash, MMC/eMMC, USB, or SD card). Unbounded framebuffer write: During RLE8 decompression, video_display_rle8_bitmap() decodes run-length encoded streams directly into the active framebuffer without validating stream bounds against the frame boundary or allocated buffer size. Pre-authentication execution window: In many embedded target configurations, the boot splash screen is rendered immediately on startup, before U-Boot calls Android Verified Boot (AVB) or FIT image signature verification routines. Storage disparity: The kernel image and rootfs are signed, but splash images are frequently stored in unsigned, user-writable partitions or external media. An attacker who writes a crafted RLE8 BMP to the boot storage can trigger an out-of-bounds write past the framebuffer during early boot, corrupting adjacent bootloader data structures, function pointers, or verification flags in memory. This hijacks the execution flow before signature checking completes. submitted by /u/Emergency_Stable_923 [link] [comments]Technical Information Security Content & DiscussionRead More