GPU VulnDB

Database/Firmware, BMC & network fabric

U-Boot: crafted NFS READLINK reply corrupts memory in the bootloader

CVSS 8.8CVE-2026-74221Firmware, BMC & network fabriccurated

Impact

nfs_readlink_reply() accepts negative or oversized symlink lengths from the NFS server and copies on that basis, corrupting bootloader memory and crashing the boot. This is a separate code path and a separate fix from the READ-reply overflow (CVE-2026-74220), and a node can be reachable through either. For diskless GPU or ARM control nodes that mount their boot tree over NFS, a hostile or spoofed server turns every boot attempt into a failed boot that needs console access to diagnose.

Who can reach it

Network position: the NFS server the node boots from, or anyone able to impersonate it on the provisioning network. No credentials needed - the client does not authenticate reply contents.

What to do

Update U-Boot to 2026.10-rc5 or later, or backport commit 1c0aff3a5fbf. Bootloader replacement means flashing each board with the node out of service. Apply it together with the READ-reply fix so a node is only taken down once. Interim mitigation is network isolation of the boot server.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.