# Das U-Boot IP defrag flaw enables RCE

Published: 2026-09-29 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/f716ea74-d5fb-57f1-930a-24487d9095b4/das-u-boot-ip-defrag-flaw-enables-rce

> A Das U-Boot bug in IP fragment reassembly lets attackers achieve arbitrary code execution via crafted duplicated last-fragment packets; fixed in 2026.07.

CERT Polska coordinated disclosure of CVE-2026-15390, a vulnerability in DENX Software Engineering's Das U-Boot bootloader affecting configurations with CONFIG_IP_DEFRAG=y enabled. The flaw lies in the IP fragment reassembly logic: U-Boot fails to properly clear its reassembly state after a complete datagram has been delivered. An attacker capable of sending fragmented IP traffic to a vulnerable device can exploit this by sending duplicated last-fragment IP packets, resulting in arbitrary code execution.

Given U-Boot's role as a bootloader widely used in embedded systems, IoT devices, and network equipment, this vulnerability could allow network-adjacent attackers to gain code execution at a very early and privileged stage of the boot process, potentially undermining any subsequent OS-level security controls. The vulnerability was responsibly reported by Mateusz Furdyna of Nokia and coordinated through CERT Polska's CVD process. There is no indication in the report of active in-the-wild exploitation.

Defenders and device manufacturers using Das U-Boot should verify whether CONFIG_IP_DEFRAG is enabled in their builds and update to release version 2026.07 or later, which includes the fix (commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa). Where immediate patching is not feasible, restricting network access to boot interfaces and disabling IP fragmentation reassembly support if not required can reduce exposure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-15390

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-15390

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f716ea74-d5fb-57f1-930a-24487d9095b4/das-u-boot-ip-defrag-flaw-enables-rce.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
