Debian Package Tracker
Register | Log in
Subscribe

u-boot

Choose email to subscribe with

general
  • source: u-boot (main)
  • version: 2025.01-3.2
  • maintainer: Vagrant Cascadian (DMD)
  • uploaders: Loïc Minier [DMD] – Clint Adams [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2021.01+dfsg-5
  • o-o-sec: 2021.01+dfsg-5+deb11u3
  • oldstable: 2023.01+dfsg-2+deb12u3
  • old-sec: 2023.01+dfsg-2+deb12u3
  • old-p-u: 2023.01+dfsg-2+deb12u3
  • stable: 2025.01-3
  • testing: 2025.01-3.2
  • unstable: 2025.01-3.2
  • exp: 2026.10~rc5-1
versioned links
  • 2021.01+dfsg-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2021.01+dfsg-5+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2023.01+dfsg-2+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2025.01-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2025.01-3.2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2026.10~rc5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • u-boot (6 bugs: 1, 3, 2, 0)
  • u-boot-amlogic-binaries
  • u-boot-asahi (1 bugs: 0, 0, 1, 0)
  • u-boot-exynos (5 bugs: 0, 5, 0, 0)
  • u-boot-exynos-binaries
  • u-boot-imx (1 bugs: 0, 0, 1, 0)
  • u-boot-mvebu
  • u-boot-omap (2 bugs: 0, 2, 0, 0)
  • u-boot-qcom
  • u-boot-qemu (4 bugs: 0, 4, 0, 0)
  • u-boot-rockchip (2 bugs: 0, 1, 1, 0)
  • u-boot-rpi (3 bugs: 0, 2, 1, 0)
  • u-boot-sifive
  • u-boot-sitara-binaries
  • u-boot-starfive
  • u-boot-stm32
  • u-boot-sunxi (12 bugs: 1, 7, 4, 0)
  • u-boot-tegra
  • u-boot-tools (4 bugs: 0, 2, 2, 0)
action needed
A new upstream version is available: 2026.07 high
A new upstream version 2026.07 is available, you should consider packaging it.
Created: 2025-11-27 Last update: 2026-10-07 04:00
14 security issues in sid high

There are 14 open security issues in sid.

14 important issues:
  • CVE-2025-70290: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
  • CVE-2025-70291:
  • CVE-2025-70292:
  • CVE-2025-70293: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.
  • CVE-2026-15390: Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
  • CVE-2026-29007: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
  • CVE-2026-29008: U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
  • CVE-2026-29009: U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
  • CVE-2026-71971: U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
  • CVE-2026-71972: U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.
  • CVE-2026-71973: U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.
  • CVE-2026-74220: U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.
  • CVE-2026-74221: U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.
  • CVE-2026-74225: U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
Created: 2026-07-14 Last update: 2026-10-02 12:02
14 security issues in forky high

There are 14 open security issues in forky.

14 important issues:
  • CVE-2025-70290: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
  • CVE-2025-70291:
  • CVE-2025-70292:
  • CVE-2025-70293: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.
  • CVE-2026-15390: Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
  • CVE-2026-29007: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
  • CVE-2026-29008: U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
  • CVE-2026-29009: U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
  • CVE-2026-71971: U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
  • CVE-2026-71972: U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.
  • CVE-2026-71973: U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.
  • CVE-2026-74220: U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.
  • CVE-2026-74221: U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.
  • CVE-2026-74225: U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
Created: 2026-07-14 Last update: 2026-10-02 12:02
14 security issues in bookworm high

There are 14 open security issues in bookworm.

14 important issues:
  • CVE-2025-70290: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
  • CVE-2025-70291:
  • CVE-2025-70292:
  • CVE-2025-70293: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.
  • CVE-2026-15390: Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
  • CVE-2026-29007: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
  • CVE-2026-29008: U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
  • CVE-2026-29009: U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
  • CVE-2026-71971: U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
  • CVE-2026-71972: U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.
  • CVE-2026-71973: U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.
  • CVE-2026-74220: U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.
  • CVE-2026-74221: U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.
  • CVE-2026-74225: U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
Created: 2026-07-14 Last update: 2026-10-02 12:02
7 security issues in bullseye high

There are 7 open security issues in bullseye.

7 important issues:
  • CVE-2025-70290: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
  • CVE-2025-70291:
  • CVE-2025-70292:
  • CVE-2025-70293: An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.
  • CVE-2026-29007: U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
  • CVE-2026-29008: U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
  • CVE-2026-29009: U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
Created: 2026-07-14 Last update: 2026-08-30 19:19
lintian reports 4 errors and 9 warnings high
Lintian reports 4 errors and 9 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-04-10 Last update: 2026-01-06 17:00
4 bugs tagged patch in the BTS normal
The BTS contains patches fixing 4 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-10-07 07:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-09-08 Last update: 2026-10-07 05:01
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2026.10-1~0, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 8a0108abab29a859d0eaacdd34532068b8f1001c
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Mon Oct 5 19:34:27 2026 -0700

    debian/changelog: Update for 2026.10.

commit 4d7ded74600803afa19b090b0d40ba6eeee52bae
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Mon Oct 5 19:33:41 2026 -0700

    debian/upstream/signing-key.asc: Update with current key.

commit a1e00e98e975bf8b72f7c41fb12e4f648da16acf
Merge: 97f6a8b10 550840658
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Mon Oct 5 19:19:31 2026 -0700

    Merge tag 'v2026.10' into debian/latest
    
    Prepare v2026.10

commit 97f6a8b108975a0984e6011a9d5653717410db3f
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sun Oct 4 12:58:30 2026 -0700

    debian/control: Update Homepage field.

commit b576f551449a98139fdd5ed1fb8c423de6f16a63
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sun Oct 4 12:57:35 2026 -0700

    debian/copyright: Update Source field.

commit 28ce95c336f12c850354f93c1a9e98968c38d94f
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sun Oct 4 12:53:51 2026 -0700

    debian/salsa-ci.yml: Drop test-crossbuild-armel.

commit 563af3c0c3b95e5a6c513e6bdf010a725cfb5d91
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sun Oct 4 12:43:37 2026 -0700

    debian/watch: Update to version 5 and switch to
    git.u-boot-project.org.

commit c32bcb10a8bc6239501e91eeb87b4e675ee4f4d3
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sun Oct 4 12:27:53 2026 -0700

    debian/salsa-ci.yml: Add test-crossbuild-riscv64.

commit 4a82f94c7d87901e2dc9ff72535db0e23dcca159
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 21:25:12 2026 -0700

    Upload u-boot 2026.10~rc5-1 to experimental.

commit b93b33602556c1c5daa1b24f4c85af4507af3adf
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 21:24:09 2026 -0700

    debian/control: Update to Standards-Version 4.7.4.

commit e4763437e7a163c3e1f0900b7d5db80498c40c30
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 21:22:07 2026 -0700

    debian/control: Update to debhelper-compat 14.

commit b0e5b5014cef55604202780d5d01253416ff9e79
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 21:13:00 2026 -0700

    debian/control: Drop Rules-Requires-Root field.

commit 023df555aaa9bab7753e575d2433754901fb17e1
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 21:12:48 2026 -0700

    debian/control: Drop Priority field.

commit 28d7609a2a18d203d3d65f98b6605cfa672def30
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 20:56:12 2026 -0700

    debian/targets.mk: Temporarily drop support for am64x_evm_r5.
    
    Currently not building, investigate later.

commit 64522505693888b1ce86dc53683948d66ce41f30
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 19:29:24 2026 -0700

    debian/patches: Avoid errors when node name is empty.

commit 7f017f26ba2240af209f4d6a92ba0182537132f5
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 19:55:02 2026 -0700

    debian/control: Build-Depends-Arch: Require libgnutls28-dev:native
    when cross building to riscv64.

commit 04c04b23611614caf348906efc6ae779cbf41a6c
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 19:13:22 2026 -0700

    debian/u-boot-omap.README.Debian: Drop obsolete name for boneblack.

commit 6a88fbde6fd83d4ec6335c520b9e63388e627c21
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 19:10:28 2026 -0700

    debian/targets.mk: Drop support for am335x_boneblack.
    
    We carried this hack for over 6 years.
    
    am335x_boneblack is dead, long live am335x_evm!

commit 9c2ecab6e327537a03359fcb987b328275471002
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 15:47:19 2026 -0700

    debian/patches: Disable dtc warning for graph_child_address.
    (Closes: #1149493)

commit 2d95d3e34de56015c31faf21d676b2e720a011ed
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 13:59:51 2026 -0700

    debian/patches: Refresh patches for v2026.10-rc5.

commit 75afad8eea6355faf7abe766513ad019d3eaf456
Merge: 97e38d87c a06e89ab0
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Sat Oct 3 13:47:21 2026 -0700

    Merge tag 'v2026.10-rc5' into debian/2026.10.x
    
    Prepare v2026.10-rc5

commit 97e38d87c2a9487de0c84be70d1553c540891f93
Author: Andreas Henriksson <andreas@fatal.se>
Date:   Mon Jun 8 14:49:19 2026 +0200

    Update debian/changelog

commit cb3da773f502bbcd430ec7ff0c85042c919ad951
Author: Andreas Henriksson <andreas@fatal.se>
Date:   Mon Jun 8 14:47:58 2026 +0200

    Cherry-pick patches from upstream for CVE-2024-42040 + CVE-2026-46728

commit 6ce476d5c81c21e4ce895e94bbe9f54277fbfbbc
Author: Chris Hofstaedtler <zeha@debian.org>
Date:   Mon Jan 5 20:16:37 2026 +0100

    Release version 2025.01-3.1

commit 19eb23eb89a67b6678a5410df96fadeb2d2e84a1
Author: Chris Hofstaedtler <zeha@debian.org>
Date:   Mon Jan 5 20:15:38 2026 +0100

    Drop remaining mips64el (qemu) targets

commit 58dc1d0f65083d6472d114691f297edc82e5f2de
Author: Chris Hofstaedtler <zeha@debian.org>
Date:   Mon Jan 5 20:13:23 2026 +0100

    Fix FTBFS with binutils/objcopy strict --target validation

commit 88cff02a181807eb5fee3182666dab58dd0e4c0b
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Tue Apr 8 16:08:14 2025 -0700

    Upload u-boot 2025.01-3 to unstable.

commit 9f7cde5548500927a9917fbae222287d6d097077
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Mar 27 11:52:56 2025 -0700

    debian/targets.mk: Fix dependencies for DHCOM targets.

commit 1861b3e56311228f699467c4d7318d40f1dc607e
Author: Marek Vasut <marex@nabladev.com>
Date:   Sat Feb 22 17:34:22 2025 +0100

    Add remaining DH electronics DHSOM based devices
    
    Add build targets for all of current upstream armhf DH electronics DHSOM
    based devices, this includes all of:
    - i.MX6 DHCOM based DRC02, PDK2, PicoITX boards
    - STM32MP15xx DHCOM based DRC02, PDK2, PicoITX boards
    - STM32MP15xx DHCOR based Avenger96, DRC Compact, Testbench boards
    
    Signed-off-by: Marek Vasut <marex@denx.de>

commit 3303fcd41f87b999dce4a2f4bcbaf513b2cc4193
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Mar 7 19:18:02 2025 -0800

    Upload u-boot 2025.01-2 to unstable.

commit bea3ae46f9342a11205f91d907b3b0d7ce72cc31
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Mar 7 18:09:40 2025 -0800

    debian/control: Update to Standards-Version 4.7.2.

commit a09f774bf9ffa8cd8bacfc489e02f4b98ba0942c
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Mar 7 17:26:44 2025 -0800

    debian/targets.mk: u-boot-omap: Drop omap3_beagle and omap4_beagle
    targets, removed upstream.

commit 2ef633636e93849bf0e5011f9673393867e6c30b
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Mar 7 17:14:20 2025 -0800

    debian/copyright: Clarify some ambiguous license declarations.

commit f556a6220eb2c97e7963d81428fc782bc664d2e5
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Mar 7 14:29:00 2025 -0800

    Upload u-boot 2025.01-1 to unstable.

commit 21894beb8261c757c0ea9d25dad72cbad2fe42f6
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Mar 7 08:54:12 2025 -0800

    debian/copyright: And further updates for 2025.01. Huge thanks to
    Frank Pursel and Diederik de Haas for all the help!

commit 758fa8ae3a72cc898c4586cba7e16fbad45312bd
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Mar 6 16:56:25 2025 -0800

    debian/copyright: Update for 2025.01.
    
    A few remaining issues to sort out, but 95% done!

commit 7746d83b6727c069e14726d366a729811c682170
Author: Diederik de Haas <didi.debian@cknow.org>
Date:   Mon Dec 16 11:10:51 2024 +0100

    debian/patches: rockchip: Drop inno-usb2 patch
    
    There are 3 reasons to drop this patch:
    1. It was NACKed by the maintainers
    2. The patch is 3.5 years old and no progress
    3. The proper solution was implemented upstream on 2021-12-30 in
       226fce6108fe ("phy: Track power-on and init counts in uclass")
    
    The above mentioned commit is included in the 2022-04 release and that
    matches perfectly with the problem as reported in bug #1024851.
    
    Closes: #1024851

commit 84ce129828d3775dc9ece41bc69e522cb5ffb4e3
Author: Diederik de Haas <didi.debian@cknow.org>
Date:   Fri Jan 17 16:36:37 2025 +0100

    debian/patches: Drop patches applied upstream
    
    This patch file was removed from the series file, but not removed in
    67bfde7c58a7 ("debian/patches: Refresh patches for 2024.10, drop patches no longer necessary.")
    
    So drop the patch file itself too.
    
    FTR: The patch was applied upstream in this commit:
    0351b659dd02 ("efi_loader: create common function to free struct efi_disk_obj")
    
    Fixes-lintian-tag: patch-file-present-but-not-mentioned-in-series

commit fa2d77f243dc8d49b3f976df823af6319c157802
Author: Diederik de Haas <didi.debian@cknow.org>
Date:   Sat Feb 22 12:48:30 2025 +0100

    debian/copyright: Add copyright data for new files in 2024.04
    
    Modified-by: Vagrant Cascadian <vagrant@debian.org>
    
    Change -only or -or-later Licenses back to short form.

commit 716a8b9f14be60a9e87d92e9c5ba3213c8a55b21
Author: Diederik de Haas <didi.debian@cknow.org>
Date:   Thu Feb 13 13:08:07 2025 +0100

    debian/copyright: Sort license stanzas
    
    Modified-by: Vagrant Cascadian <vagrant@debian.org>
    
    Revert changes to long-form GPL/LGPL License names.

commit ab88925bb1e9fa4ed1128d9ba81aad2571a8a344
Merge: 8d3bde151 d933c0904
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Wed Jan 8 09:19:25 2025 -0800

    Merge remote-tracking branch 'salsa/merge-requests/41' into debian/latest

commit 8d3bde1512e2fe54b3f94a29ff5783cf3a0f76ca
Merge: 1fcaa7133 f3bee4fc7
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Wed Jan 8 09:19:19 2025 -0800

    Merge remote-tracking branch 'salsa/merge-requests/45' into debian/latest

commit d933c0904a9127294bd1ee5c91a7c17c3b6f5ea4
Author: Martyn Welch <martyn.welch@collabora.com>
Date:   Fri Apr 5 15:40:53 2024 +0100

    sitara: Package keys required for signing boot firmware
    
    The AM625 and similiar SoCs require set boot firmware blobs to be built
    which include, among other things, the U-Boot SPL binaries.  Depending
    on the variant, one of two keys needs to be used to sign this boot
    firmware for them to be accepted by the ROM firmware (unless alternative
    keys are blown into the device in question). The U-Boot source can
    compile these firmware blobs, however it would require access to the
    various other components at build time. As some of these components are
    not suitably licensed to be included in the main Debian repositories we
    can't assemble them at build time and must do this at a later date.
    
    In recent releases of U-Boot, these keys have been included in the
    U-Boot source tree. Package the signing keys so that they can be used
    when the firmware blobs are assembled.
    
    Signed-off-by: Martyn Welch <martyn.welch@collabora.com>

commit f3bee4fc7f9f196f8c57042d664a9c949ed98a6d
Author: Martyn Welch <martyn.welch@collabora.com>
Date:   Tue Jan 7 18:25:01 2025 +0000

    sitara: Update dtb location
    
    The device tree we wish to package is now in the "upstream" directory,
    update targets appropriately.
    
    Signed-off-by: Martyn Welch <martyn.welch@collabora.com>

commit 6150ee27fe64f2ce02d50799a1d866e3ea8b8a36
Author: Martyn Welch <martyn.welch@collabora.com>
Date:   Mon Feb 5 13:49:53 2024 +0000

    sitara: Don't attempt to build final firmware images
    
    The final firmware images require access to firmware not yet present in
    linux-firmware. In certain instances it will be either desirable or
    required to sign the elements that are included in the final firmware
    images with device specific keys, which won't be present at build time.
    
    Build and package the firmware elements that are required to form the
    firmware images at a later date.
    
    Signed-off-by: Martyn Welch <martyn.welch@collabora.com>

commit 0aa8c4682dcd55e6e11fd935ec84db811192497c
Author: Martyn Welch <martyn.welch@collabora.com>
Date:   Tue Jan 7 12:05:33 2025 +0000

    debian/targets.mk: Re-enable sitara
    
    The following commits in this series fix the sitara build.
    
    Signed-off-by: Martyn Welch <martyn.welch@collabora.com>

commit 1fcaa7133b667c76b3bf5809a542b5a109bdc6e6
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Tue Jan 7 14:12:00 2025 -0800

    debian/changelog: Bump for 2025.01 release.

commit d0a640df1b37dd2531c37fe9f30211d2de90378b
Merge: b11e0fe49 6d41f0a39
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Tue Jan 7 14:11:12 2025 -0800

    Merge tag 'v2025.01' into debian/latest
    
    Prepare v2025.01

commit b11e0fe494656bbccb68b0b57b95fd8c8d7ba564
Merge: 657432b79 d04b8bd35
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Tue Jan 7 22:10:14 2025 +0000

    Merge branch 'wip/obbardc/qcom-additional-targets' into 'debian/latest'
    
    Add me to dragonboard820c qcom maintainers & Enable qcm6490 qcom device.
    
    See merge request debian/u-boot!44

commit d04b8bd3595d4d46f981bda52df32a22e41e1552
Author: Christopher Obbard <obbardc@debian.org>
Date:   Tue Jan 7 12:14:24 2025 +0000

    debian/control: Add xxd to B-d
    
    Required for qcom/qcm6490 target.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit eeafd3ff0980777ec994148f92e79cab4bd5eabf
Author: Christopher Obbard <obbardc@debian.org>
Date:   Tue Jan 7 11:52:05 2025 +0000

    debian/targets.mk: Enable qcm6490 qcom device
    
    I have this device and want to see it enabled in Debian. Add the platform
    to the u-boot-qcom package and add my details to the maintainership.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit 977d357a8f20f45c44980dcdf9b92bc1395be97a
Author: Christopher Obbard <obbardc@debian.org>
Date:   Tue Jan 7 11:50:24 2025 +0000

    debian/targets.mk: Add me to dragonboard820c maintainers
    
    I have this board, add my mail to the maintainer list.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit 6d41f0a39d6423c8e57e92ebbe9f8c0333a63f72
Author: Tom Rini <trini@konsulko.com>
Date:   Mon Jan 6 18:54:44 2025 -0600

    Prepare v2025.01
    
    Signed-off-by: Tom Rini <trini@konsulko.com>

commit 657432b79ee121e7381ca160e96e1c79f4e0b23a
Merge: 95b4b432e f864d428f
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Mon Jan 6 20:57:57 2025 +0000

    Merge branch 'wip/obbardc/rockchip-spi' into 'debian/latest'
    
    debian/targets.mk: Include u-boot-rockchip-spi.bin
    
    See merge request debian/u-boot!43

commit f864d428fd3b532ef8bdef14c913e33fecfa6300
Author: Christopher Obbard <obbardc@debian.org>
Date:   Mon Jan 6 19:31:18 2025 +0000

    debian/targets.mk: Include u-boot-rockchip-spi.bin
    
    For targets which have `CONFIG_ROCKCHIP_SPI_IMAGE=y` set in the upstream
    config include the image in the u-boot-rockchip package so that users
    can install it to the SPI flash if they wish.
    
    Currently `debian/bin/u-boot-install-rockchip` does not attempt to
    install this binary to SPI flash. It is up to users to do so.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit 95b4b432e4b6f126813ad64d8374eac17b9bcb1e
Author: Christopher Obbard <obbardc@debian.org>
Date:   Wed Jul 17 12:47:17 2024 +0100

    debian/targets.mk: Add support for rock-4se-rk3399
    
    Support the ROCK 4SE.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit 4a3224612db3706ef731de6e2f1f1012414f3b00
Author: Christopher Obbard <obbardc@debian.org>
Date:   Fri Jul 12 11:25:20 2024 +0100

    debian/targets.mk: Build u-boot-rockchip.bin
    
    u-boot-rockchip.bin is built by upstream to be flashed directly to the
    eMMC/SD card. Build it for all supported targets upstream.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit 653df61407288c9ab0d49a63c9e2251395001044
Author: Christopher Obbard <obbardc@debian.org>
Date:   Fri Jul 12 11:05:28 2024 +0100

    debian/targets.mk: Rework rock-pi-4 to match other devices
    
    The formatting of the rock-pi-4 target is wrong. Rework it.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit e7b2b2406162edbba2df748b279191dc93cfe37e
Author: Christopher Obbard <obbardc@debian.org>
Date:   Fri Jul 12 10:59:53 2024 +0100

    debian/targets.mk: Update my contact address
    
    Since I now have a debian email; use it for all future contact.
    
    Signed-off-by: Christopher Obbard <obbardc@debian.org>

commit bc88d461adb7adc45e0c425655fcb30f596c81f4
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Jan 3 23:11:58 2025 -0800

    debian/control: Add libgnutls28-dev:native to Build-Depends to fix
    cross-building of armel and armhf.

commit 00927c09fc0eec7e6a26d6a60421cb100d6de324
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Jan 3 23:09:42 2025 -0800

    debian/control: Move libgnutls28-dev to Build-Depends. Fixes build
    failure in arch:all only build.

commit 8627989504c91958ef5102e56ac47477a1b04bd8
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Fri Jan 3 21:50:46 2025 -0800

    debian/targets.mk: disable u-boot-sitara targets as they are failing
    to build.

commit 7320c3eca45111a6960214aad8cd50ce9aa5a0fb
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Jan 2 16:54:51 2025 -0800

    debian/targets.mk: Adjust for changed location for rockchip .dtb
    files.

commit 4f67864507c2a4963e145e09b251a79830eb6623
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Jan 2 14:34:49 2025 -0800

    debian/changelog: wrap long lines.

commit a432993295f4638d2e9d307b1f2182a48d02acd4
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Jan 2 14:17:11 2025 -0800

    Remove cruft not present in upstream tarball.

commit 6081a5b66de5cce14c2b033da8cb34211e7e19c1
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Jan 2 14:09:30 2025 -0800

    debian/changelog: Update for v2025.01-rc6.

commit 0e2ff2f26a472993a2a60c9210c0e06e7681fb02
Author: Vagrant Cascadian <vagrant@debian.org>
Date:   Thu Jan 2 14:02:15 2025 -0800

    debian/patches: Refresh qemu/efi-secure-boot.patch for v2025.01-rc6.

commit e7713a78829250b925d6377ee26c7b0745727feb
Author: Prasanth Babu Mantena <p-mantena@ti.com>
Date:   Wed Dec 18 18:30:45 2024 +0530

    dma: ti: k3-udma: Fix BCDMA probe by adding check for MMR_RFLOW
    
    RFLOW config related MMR does not exist incase of BCDMA.
    Add check to bypass the RFLOW MMR extraction.
    Without this, the probe sequence fails checking for
    the MMR_RFLOW region, which is valid only for packet based
    DMA and obselete for BCDMA.
    
    Fixes: 5abb694d6016 ("dma: ti: k3-udma: Add support for native configuration of chan/flow")
    Signed-off-by: Prasanth Babu Mantena <p-mantena@ti.com>
    Tested-by: Jonathan Humphreys <j-humphreys@ti.com>

commit 4be40460758057b9a85b0303dc072c108813cdf6
Author: Tom Rini <trini@konsulko.com>
Date:   Mon Dec 30 22:07:58 2024 -0600

    Prepare v2025.01-rc6
    
    Signed-off-by: Tom Rini <trini@konsulko.com>

commit 9bb02f7f4533fbb48c8a5822b4b41a2e527b949c
Author: Abbarapu Venkatesh Yadav <venkyada@qti.qualcomm.com>
Date:   Mon Dec 30 12:32:06 2024 +0530

    mtd: spi-nor: Fix the spi_nor_read() when config SPI_STACKED_PARALLEL is enabled
    
    Update the spi_nor_read() function based on the config SPI_FLASH_BAR
    and update the length and bank calculation by spliting the memory of
    16MB size banks only when the address width is 3byte.
    Fix the read issue for 4byte address width by passing the entire
    length to the read function.
    
    Fixes: 5d40b3d384 ("mtd: spi-nor: Add parallel and stacked memories support")
    Signed-off-by: Venkatesh Yadav Abbarapu <venkatesh.abbarapu@amd.com>

commit cb7410257ac930a6fb05f1c63b291b7d399f19f2
Merge: 3391587e3 0be26928b
Author: Tom Rini <trini@konsulko.com>
Date:   Thu Dec 26 10:21:22 2024 -0600

    Merge tag 'doc-2025-01-rc6' of https://source.denx.de/u-boot/custodians/u-boot-efi
    
    Pull request doc-2025-01-rc6
    
    Fix a number of typos
    
    * cmd: bootmenu typo 'read'
    * cmd/rng: fix long help text
    * crypto: typo volatge
    * board: freescale: typo volatge
    * scripts: add volatge to spelling.txt
    * doc: fit: Format image tree source example

commit 0be26928bfc4f2a34df3eb447fee718d3551217c
Author: Heinrich Schuchardt <xypron.glpk@gmx.de>
Date:   Wed Dec 11 17:31:53 2024 +0100

    scripts: add volatge to spelling.txt
    
    To avoid future misspells add volatge to spelling.txt.
    
    Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>

commit 3391587e3fe22db6c71882f652e13543a4501694
Author: Tom Rini <trini@konsulko.com>
Date:   Mon Dec 23 20:40:49 2024 -0600

    Prepare v2025.01-rc5
    
    Signed-off-by: Tom Rini <trini@konsulko.com>
Created: 2026-10-04 Last update: 2026-10-06 04:32
6 open merge requests in Salsa normal
There are 6 open merge requests for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-10-02 Last update: 2026-10-02 06:31
14 low-priority security issues in trixie low

There are 14 open security issues in trixie.

14 issues left for the package maintainer to handle:
  • CVE-2025-70290: (needs triaging) An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.
  • CVE-2025-70291: (needs triaging)
  • CVE-2025-70292: (needs triaging)
  • CVE-2025-70293: (needs triaging) An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts.
  • CVE-2026-15390: (needs triaging) Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
  • CVE-2026-29007: (needs triaging) U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, allowing remote attackers to read beyond TCP segment boundaries by crafting a malicious packet with a mismatched IP total length and TCP data offset field. Attackers can send a packet with an IP total length of 40 bytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_options() to read 40 bytes past the end of the TCP segment, potentially corrupting connection state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP window calculations.
  • CVE-2026-29008: (needs triaging) U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.
  • CVE-2026-29009: (needs triaging) U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, potentially achieving memory corruption and control over the NFS client state machine.
  • CVE-2026-71971: (needs triaging) U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.
  • CVE-2026-71972: (needs triaging) U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.
  • CVE-2026-71973: (needs triaging) U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.
  • CVE-2026-74220: (needs triaging) U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.
  • CVE-2026-74221: (needs triaging) U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.
  • CVE-2026-74225: (needs triaging) U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-14 Last update: 2026-10-02 12:02
debian/patches: 12 patches to forward upstream low

Among the 12 debian patches available in version 2025.01-3.2 of the package, we noticed the following issues:

  • 12 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-15 21:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-06-15 15:18
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-10-04] Accepted u-boot 2026.10~rc5-1 (source) into experimental (Vagrant Cascadian)
  • [2026-07-16] Accepted u-boot 2025.01-3+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Andreas Henriksson)
  • [2026-06-24] Accepted u-boot 2023.01+dfsg-2+deb12u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Andreas Henriksson)
  • [2026-06-23] Accepted u-boot 2021.01+dfsg-5+deb11u3 (source) into oldoldstable-security (Andreas Henriksson)
  • [2026-06-23] Accepted u-boot 2023.01+dfsg-2+deb12u3 (source) into oldstable-security (Debian FTP Masters) (signed by: Andreas Henriksson)
  • [2026-06-18] u-boot 2025.01-3.2 MIGRATED to testing (Debian testing watch)
  • [2026-06-15] Accepted u-boot 2025.01-3.2 (source) into unstable (Andreas Henriksson)
  • [2026-01-11] u-boot 2025.01-3.1 MIGRATED to testing (Debian testing watch)
  • [2026-01-05] Accepted u-boot 2025.01-3.1 (source) into unstable (Chris Hofstaedtler) (signed by: Christian Hofstaedtler)
  • [2025-12-07] Accepted u-boot 2023.01+dfsg-2+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Daniel Leidert)
  • [2025-09-30] Accepted u-boot 2021.01+dfsg-5+deb11u2 (source) into oldoldstable-security (Daniel Leidert)
  • [2025-05-01] Accepted u-boot 2021.01+dfsg-5+deb11u1 (source) into oldstable-security (Daniel Leidert)
  • [2025-04-14] u-boot 2025.01-3 MIGRATED to testing (Debian testing watch)
  • [2025-04-08] Accepted u-boot 2025.01-3 (source) into unstable (Vagrant Cascadian)
  • [2025-03-13] u-boot 2025.01-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-08] Accepted u-boot 2025.01-2 (source) into unstable (Vagrant Cascadian)
  • [2025-03-07] Accepted u-boot 2025.01-1 (source) into unstable (Vagrant Cascadian)
  • [2025-01-15] u-boot 2024.01+dfsg-7 MIGRATED to testing (Debian testing watch)
  • [2025-01-09] Accepted u-boot 2024.01+dfsg-7 (source) into unstable (Vagrant Cascadian)
  • [2025-01-08] u-boot 2024.01+dfsg-6 MIGRATED to testing (Debian testing watch)
  • [2025-01-02] Accepted u-boot 2024.01+dfsg-6 (source) into unstable (Vagrant Cascadian)
  • [2024-05-03] u-boot 2024.01+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2024-04-22] Accepted u-boot 2023.01+dfsg-2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-04-19] Accepted u-boot 2024.01+dfsg-5 (source) into unstable (Vagrant Cascadian)
  • [2024-04-19] Accepted u-boot 2024.01+dfsg-4 (source all amd64) into experimental (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-03-20] Accepted u-boot 2024.01+dfsg-3 (source) into unstable (Vagrant Cascadian)
  • [2024-03-20] Accepted u-boot 2024.01+dfsg-2 (source) into unstable (Vagrant Cascadian)
  • [2024-01-16] u-boot 2024.01+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-10] Accepted u-boot 2024.01+dfsg-1 (source) into unstable (Vagrant Cascadian)
  • [2024-01-07] Accepted u-boot 2024.01~rc6+dfsg-2 (source armel) into experimental (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • 1
  • 2
bugs [bug history graph]
  • all: 62 63
  • RC: 3
  • I&N: 34
  • M&W: 24 25
  • F&P: 1
  • patch: 4
links
  • homepage
  • lintian (4, 9)
  • buildd: logs, exp, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2025.10-0ubuntu4
  • 16 bugs
  • patches for 2025.10-0ubuntu4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing