CVE-2026-15390

CRITICALCVSS 9/10

Last modified

CVE-2026-15390 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07..

Description

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
DENX Software EngineeringDas U-Boot>= 2009.08, <= 2026.07

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-15390?
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
How severe is CVE-2026-15390?
CVE-2026-15390 has a CVSS score of 9/10 (CRITICAL severity).
How do I fix CVE-2026-15390?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-15390?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST