News

USN-8884-1: four U-Boot flaws, risk of code execution

Ubuntu fixes four vulnerabilities in U-Boot that could lead to code execution or denial of service on embedded systems.

UptimeMag editorial team · 6 October 2026 · 2 min read

USN-8884-1: quattro falle in U-Boot, rischio esecuzione di codice

Ubuntu published the security advisory USN-8884-1 on 6 October 2026, containing four fixes for U-Boot, the bootloader used on embedded systems. This concerns anyone managing network appliances, ARM devices or custom boot images based on Ubuntu, rather than typical x86 production servers.

The vulnerabilities

According to the official Ubuntu advisory, the issues fixed are:

  • CVE-2025-70290: improper handling of malformed ZFS metadata, discovered by Timo Preißl. This can cause an integer overflow and out-of-bounds memory access, potentially leading to arbitrary code execution or denial of service.
  • CVE-2025-70293: incorrect calculation of buffer sizes when processing ext4 file systems, also found by Timo Preißl. Same effect as the previous one: integer overflow and out-of-bounds access. Affects Ubuntu 18.04, 20.04, 22.04, 24.04 and 26.04 LTS.
  • CVE-2026-15390: improper handling of fragmented IP traffic when IP defragmentation is enabled, discovered by Mateusz Furdyna. An attack using crafted IP packets can corrupt memory and lead to code execution.
  • CVE-2026-71971: improper handling of fragmented IP traffic during network boot, discovered by Shahriyar Jalayeri and Mehrun P. Hunter. Can cause an out-of-bounds write, resulting in denial of service.

Affected packages and fixed versions

The packages affected are u-boot-imx, u-boot-qemu and u-boot-tools. The patched versions, as stated in the advisory text:

Release Fixed version
26.04 LTS (resolute) 2025.10-0ubuntu2.1
24.04 LTS (noble) 2025.10-0ubuntu0.24.04.3
22.04 LTS (jammy) 2022.01+dfsg-2ubuntu2.8
20.04 LTS (focal) 2021.01+dfsg-3ubuntu0~20.04.6+esm1 (Ubuntu Pro)
18.04 LTS (bionic) 2020.10+dfsg-1ubuntu0~18.04.3+esm1 (Ubuntu Pro)
16.04 LTS (xenial) 2016.01+dfsg1-2ubuntu5+esm1 (Ubuntu Pro, Legacy Support add-on)

For 16.04, 18.04 and 20.04 LTS, the patch is only available with Ubuntu Pro, which covers up to five machines free of charge.

What to do

A standard apt update && apt upgrade applies the fixes on the supported releases. Those running 16.04, 18.04 or 20.04 LTS should check their Ubuntu Pro subscription to receive the updated package. Full details, including the CVE entries, are available in the official advisory USN-8884-1 at ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.