Ubuntu Patches Four U Boot Flaws Putting Embedded Device Boot Processes At Risk
Canonical has published security notice USN-8884-1, covering four vulnerabilities in U-Boot, the open source bootloader used to start Linux on many embedded, IoT and single board systems. Two of the flaws sit in filesystem parsing. CVE-2025-70290 involves malformed ZFS file system metadata, and CVE-2025-70293 stems from incorrect buffer size calculations when processing ext4 file systems. Both can trigger an integer overflow and out of bounds memory access, leading to arbitrary code execution or denial of service. The ext4 issue affects Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS and 26.04 LTS.
The remaining two issues are reachable over the network rather than through storage. CVE-2026-15390 concerns handling of fragmented IP traffic when IP defragmentation is enabled, where crafted fragments can corrupt memory and allow arbitrary code execution. CVE-2026-71971 covers similar fragment handling during network boot, with the result being an out of bounds write and denial of service. In each case the attacker supplies untrusted input that U-Boot parses before operating system protections exist. The advisory does not publish proof of concept code or exploitation steps.
Risk is shaped by position more than volume. The filesystem bugs require a device to boot from attacker influenced ZFS or ext4 media, while the fragment handling bugs require an adjacent network position where devices perform network boot. Code running at bootloader stage sits beneath the kernel, so successful exploitation would undermine later security controls. FIRST EPSS places exploitation probability over the next 30 days at 0.7 percent for CVE-2025-70290, 0.8 percent for CVE-2025-70293, 0.3 percent for CVE-2026-15390 and 0.4 percent for CVE-2026-71971.
Attack Surface
IoT, Infrastructure, Endpoint OS
Tactics
Execution, Initial Access, Persistence, Impact
Techniques
- T1542.003 – Pre-OS Boot: Bootkit
- T1210 – Exploitation of Remote Services
- T1499.004 – Endpoint Denial of Service: Application or System Exploitation
- T1200 – Hardware Additions
SuperPRO's Threat Countermeasures Procedures
- Inventory u-boot packages across the Ubuntu estate with 'dpkg -l | grep u-boot', noting that USN-8884-1 records the ext4 flaw CVE-2025-70293 as affecting only Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS and 26.04 LTS.
- Install the fixed u-boot packages via 'apt install –only-upgrade' using the exact per-release package versions enumerated in USN-8884-1 for the running Ubuntu release, then reboot the device so the updated bootloader is the one actually executed.
- Re-flash or rebuild any device images that embed a U-Boot binary onto SPI flash, eMMC or SD card, because an apt package update does not replace a bootloader already written to the boot medium.
- Where fragment reassembly is not required, rebuild U-Boot with IP defragmentation support disabled (the CONFIG_IP_DEFRAG build option), which removes the code path behind CVE-2026-15390 and CVE-2026-71971.
- Disable network boot in bootcmd on devices that do not need it, and restrict DHCP and TFTP (UDP/69) for devices that do to a dedicated provisioning VLAN with no untrusted hosts attached.
- Lock boot order so devices do not automatically parse removable ZFS or ext4 media, and enable U-Boot verified boot signature checking so only signed images are loaded, limiting exposure to CVE-2025-70290 and CVE-2025-70293.
- Alert on repeated unexplained reboots or serial console crash output during the bootloader stage on network-booting fleets, which would be the observable effect of the out-of-bounds write in CVE-2026-71971.