Tag
#cve
U-Boot TCP/NFS Vulnerabilities: Integer Underflow and Buffer Overflow in the World's Most Popular Bootloader
Three CVEs in U-Boot's network stack: a TCP integer underflow that corrupts packet processing and an NFS path overflow that escapes a 2048-byte buffer.
Four Vulnerabilities in barebox: From DHCP Parsing to EFI PE Loading
Four CVEs across barebox's network stack, filesystem layer, and EFI loader: an unbounded DHCP option scan, two ext4 parsing flaws, and a PE virtual-size integer overflow.
Same Workflow, New Target: AI-Assisted Discovery of CVE-2026-29004 in BusyBox
How the AI workflow that found a strongSwan zero-day discovered a 9-year-old heap overflow in BusyBox's DHCPv6 client, plus a full PoC walkthrough.
Finding a 15-Year-Old Zero-Day in strongSwan with AI-Assisted Code Analysis
How I discovered CVE-2026-25075, a bug hiding in strongSwan since 2011, using a structured multi-pass AI analysis workflow.