Packages
- u-boot - A boot loader for embedded systems
Details
Timo Preißl discovered that U-Boot incorrectly handled certain malformed
ZFS file system metadata. An attacker could possibly use this issue to
trigger an integer overflow and out-of-bounds memory access, resulting in
arbitrary code execution or a denial of service. (CVE-2025-70290)
Timo Preißl discovered that U-Boot incorrectly calculated buffer sizes when
processing certain ext4 file systems. An attacker could possibly use this
issue to trigger an integer overflow and out-of-bounds memory access,
resulting in arbitrary code execution or a denial of service. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2025-70293)
Mateusz Furdyna discovered that U-Boot incorrectly handled certain
fragmented IP traffic when IP defragmentation was enabled. An attacker
could possibly use...
Timo Preißl discovered that U-Boot incorrectly handled certain malformed
ZFS file system metadata. An attacker could possibly use this issue to
trigger an integer overflow and out-of-bounds memory access, resulting in
arbitrary code execution or a denial of service. (CVE-2025-70290)
Timo Preißl discovered that U-Boot incorrectly calculated buffer sizes when
processing certain ext4 file systems. An attacker could possibly use this
issue to trigger an integer overflow and out-of-bounds memory access,
resulting in arbitrary code execution or a denial of service. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2025-70293)
Mateusz Furdyna discovered that U-Boot incorrectly handled certain
fragmented IP traffic when IP defragmentation was enabled. An attacker
could possibly use this issue to corrupt memory by sending crafted IP
fragments, resulting in arbitrary code execution. (CVE-2026-15390)
Shahriyar Jalayeri and Mehrun P. Hunter discovered that U-Boot incorrectly
handled certain fragmented IP traffic during network boot when IP
defragmentation was enabled. An attacker could possibly use this issue to
trigger an out-of-bounds write, resulting in a denial of service.
(CVE-2026-71971)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | u-boot-imx – 2025.10-0ubuntu2.1 | ||
| u-boot-qemu – 2025.10-0ubuntu2.1 | |||
| u-boot-tools – 2025.10-0ubuntu2.1 | |||
| 24.04 LTS noble | u-boot-imx – 2025.10-0ubuntu0.24.04.3 | ||
| u-boot-qemu – 2025.10-0ubuntu0.24.04.3 | |||
| u-boot-tools – 2025.10-0ubuntu0.24.04.3 | |||
| 22.04 LTS jammy | u-boot-imx – 2022.01+dfsg-2ubuntu2.8 | ||
| u-boot-qemu – 2022.01+dfsg-2ubuntu2.8 | |||
| u-boot-tools – 2022.01+dfsg-2ubuntu2.8 | |||
| 20.04 LTS focal | u-boot-imx – 2021.01+dfsg-3ubuntu0~20.04.6+esm1 | ||
| u-boot-qemu – 2021.01+dfsg-3ubuntu0~20.04.6+esm1 | |||
| u-boot-tools – 2021.01+dfsg-3ubuntu0~20.04.6+esm1 | |||
| 18.04 LTS bionic | u-boot-imx – 2020.10+dfsg-1ubuntu0~18.04.3+esm1 | ||
| u-boot-qemu – 2020.10+dfsg-1ubuntu0~18.04.3+esm1 | |||
| u-boot-tools – 2020.10+dfsg-1ubuntu0~18.04.3+esm1 | |||
| 16.04 LTS xenial | u-boot-imx – 2016.01+dfsg1-2ubuntu5+esm1 | ||
| u-boot-tools – 2016.01+dfsg1-2ubuntu5+esm1 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.