Re: [security] Report of possible global heap overflow in U-Boot's fastboot-over-TCP server by authenticated peer (ANT-2026-5D7F7SAQ)
Mattijs Korpershoek <[email protected]>
| Newsgroups | org.u-boot-project.lists.u-boot |
|---|---|
| Message-ID | <[email protected]> |
Hi Arthur, Thank you for the report. On Thu, Aug 06, 2026 at 14:40, Arthur Chan <[email protected]> wrote: > Hello U-Boot maintainers, > > I'd like to report a High-severity security issue in U-Boot (https://github.com/u-boot/u-boot / https://git.u-boot-project.org/u-boot/u-boot) related to possible global heap overflow in U-Boot's fastboot-over-TCP server by authenticated peer. > > I have attached 3 files with this email as described below. > 1) report.md: A full description of the vulnerability and how to reproduce it, together with suggested fix of the issue. > 2) Dockerfile: A Dockerfile for demonstrating the issue. > 3) driver.c: Work with the Dockerfile to demonstrate the issue. > > Attribution > ----------- > Please attribute Claude and Ada Logics. This issue was found by Anthropic from using agents to study security of open source projects, and I am from Ada Logics helping validate the found issues and creating the report manually and notify the maintainers. > > Disclosure > ---------- > This report follows a 90-day coordinated disclosure deadline. I'm happy to coordinate on the exact timing and to provide any further detail you need. If you wish to help the U-Boot community, please consider contributing a patch to fix this. See https://docs.u-boot-project.org/en/latest/develop/sending_patches.html#sending-patches Thanks Mattijs