Das U-Boot IP defrag flaw enables RCE
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
A Das U-Boot bug in IP fragment reassembly lets attackers achieve arbitrary code execution via crafted duplicated last-fragment packets; fixed in 2026.07.
CERT Polska coordinated disclosure of CVE-2026-15390, a vulnerability in DENX Software Engineering's Das U-Boot bootloader affecting configurations with CONFIG_IP_DEFRAG=y enabled. The flaw lies in the IP fragment reassembly logic: U-Boot fails to properly clear its reassembly state after a complete datagram has been delivered. An attacker capable of sending fragmented IP traffic to a vulnerable device can exploit this by sending duplicated last-fragment IP packets, resulting in arbitrary code execution.
Given U-Boot's role as a bootloader widely used in embedded systems, IoT devices, and network equipment, this vulnerability could allow network-adjacent attackers to gain code execution at a very early and privileged stage of the boot process, potentially undermining any subsequent OS-level security controls. The vulnerability was responsibly reported by Mateusz Furdyna of Nokia and coordinated through CERT Polska's CVD process. There is no indication in the report of active in-the-wild exploitation.
Defenders and device manufacturers using Das U-Boot should verify whether CONFIG_IP_DEFRAG is enabled in their builds and update to release version 2026.07 or later, which includes the fix (commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa). Where immediate patching is not feasible, restricting network access to boot interfaces and disabling IP fragmentation reassembly support if not required can reduce exposure.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-15390
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,271 reports from 154 sources, 2,726 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs