
CVE-2026-29008: a single TCP SYN+ACK packet can crash U-Boot before your device finishes booting. Integer underflow in tcp_rx_state_machine(). Here's what broke and who's affected.
Post summary
The CVE reveals that a single TCP SYN+ACK packet can trigger an integer underflow in tcp_rx_state_machine(), crashing U‑Boot before boot completion.


