Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-29007 Details

Description

U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-125Out-of-bounds Read[email protected]

Affected Products

ProductVersions
denx u-boot
< 2026.04
2026.04 rc1
2026.04 rc2
2026.04 rc3

CPE

  • cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
  • cpe:2.3:a:denx:u-boot:2026.04:rc1:*:*:*:*:*:*
  • cpe:2.3:a:denx:u-boot:2026.04:rc2:*:*:*:*:*:*
  • cpe:2.3:a:denx:u-boot:2026.04:rc3:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-29007
NVD Published Date:
Jul 8, 2026
NVD Last Modified:
Jul 22, 2026
Source:
[email protected]
CVE-2026-29007 Details - Not Deferred