Re: [security] Report of possible global heap overflow in U-Boot's fastboot-over-TCP server by authenticated peer (ANT-2026-5D7F7SAQ)

Mattijs Korpershoek <[email protected]>
Newsgroups org.u-boot-project.lists.u-boot
Message-ID <[email protected]>
Hi Arthur,

Thank you for the report.

On Thu, Aug 06, 2026 at 14:40, Arthur Chan <[email protected]> wrote:

> Hello U-Boot maintainers,
>
> I'd like to report a High-severity security issue in U-Boot (https://github.com/u-boot/u-boot / https://git.u-boot-project.org/u-boot/u-boot) related to possible global heap overflow in U-Boot's fastboot-over-TCP server by authenticated peer.
>
> I have attached 3 files with this email as described below.
> 1) report.md: A full description of the vulnerability and how to reproduce it, together with suggested fix of the issue.
> 2) Dockerfile: A Dockerfile for demonstrating the issue.
> 3) driver.c: Work with the Dockerfile to demonstrate the issue.
>
> Attribution
> -----------
> Please attribute Claude and Ada Logics. This issue was found by Anthropic from using agents to study security of open source projects, and I am from Ada Logics helping validate the found issues and creating the report manually and notify the maintainers.
>
> Disclosure
> ----------
> This report follows a 90-day coordinated disclosure deadline. I'm happy to coordinate on the exact timing and to provide any further detail you need.

If you wish to help the U-Boot community, please consider contributing a
patch to fix this.

See
https://docs.u-boot-project.org/en/latest/develop/sending_patches.html#sending-patches

Thanks
Mattijs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.