GPU VulnDB

Database/Firmware, BMC & network fabric

U-Boot: integer overflow in ZFS metadata parsing gives out-of-bounds access during boot

CVE-2025-70290Firmware, BMC & network fabriccurated

Impact

Malformed ZFS on-disk metadata causes an incorrect allocation size and a subsequent out-of-bounds memory access while the bootloader reads the filesystem, which the report describes as a crash or possible code execution during boot. Exposure is narrow: U-Boot is the boot firmware on BMCs, ARM server platforms and DPUs rather than on typical x86 GPU hosts, the ZFS reader has to be compiled into the image, and the attacker needs to control the pool U-Boot reads. What keeps it worth tracking is the stage it runs at, before any operating system integrity control exists. Fixed in U-Boot 2026.04.

Who can reach it

Someone able to write the boot media or ZFS pool that U-Boot reads at startup: physical access, a compromised provisioning path, or an attacker-controlled boot source. No authentication exists at this stage.

What to do

Move to U-Boot 2026.04 or later where the platform vendor ships it; on BMCs, DPUs and appliances that means waiting for a vendor firmware image and flashing the device with the node out of service. Builds without ZFS support are not affected. Note the record carries no vendor advisory or upstream commit, only the NVD entry and the reporter's writeup, so no per-platform fixed firmware level is known.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.