CVE-2026-15390EPSS p19.2%
CVE-2026-15390CVE-2026-15390
Description
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.
Scoring
| EPSS | 0.29% probability of exploitation · percentile 19.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |