
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
securityvulnerabilityU-BootSecure BootCVE-2026-71972bootloaderexploitbuffer overflowRLE8bitmap
Researchers discovered a pre-authentication Secure Boot bypass vulnerability in U-Boot's RLE8 bitmap decoder (video_display_rle8_bitmap()) that allows an unbounded write to the framebuffer during boot splash screen rendering. The vulnerability occurs because the decoder does not validate stream bounds against the frame boundary or allocated buffer size when decompressing RLE8 BMP images. An attacker can exploit this by placing a crafted RLE8 BMP file in unsigned, user-writable storage partitions, triggering an out-of-bounds write that corrupts bootloader data structures or function pointers before signature verification completes, thereby hijacking execution flow.