← Back to CVE intelligence
CVE intelligence

CVE-2026-71973

Vulnerability intelligence

Published Sep 29, 2026Sources checked Oct 4, 2026
5.2MEDIUMCVSS out of 10
What this means

Review the available evidence

CVE-2026-71973 and is rated Medium severity with a CVSS score of 5.2. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

What to do next

Remediation and response

CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-71973?

U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.