DEV Community

Raghu Bharadwaj
Raghu Bharadwaj

Posted on Originally published at techveda.live

Open-Source Device CVEs: What to Patch by Vertical (September 2026)

Originally published on TECH VEDA: Open-Source Device CVEs: What to Patch by Vertical (September 2026). This is a monthly series covering the device stack beyond the Linux kernel.

September 2026 brought 36 open-source device CVEs and advisories worth acting on across 14 packages: U-Boot, OpenSSL, wolfSSL, expat, zlib, libxml2, BusyBox, Python, FFmpeg, GStreamer, WebKitGTK, Chromium, containerd, BlueZ. Two of them are in the CISA Known Exploited Vulnerabilities catalog. Both are Chromium V8 bugs. A proof of concept is published for one zlib issue. Most items have a fix upstream. Several exist only as commits or release candidates, and BusyBox has no upstream fix yet. The action is to update each affected package to the fixed version, take your distribution's patched package or cherry-pick where there is no release, and rebuild the image. 14 packages are affected.

This is the device stack beyond the kernel. It includes the bootloader, the C library, the TLS libraries, the media pipeline, the language runtimes and the container runtime that sit inside a shipped image. Which of these open-source device CVEs matter to you depends on what is in your image and your software bill of materials (SBOM). The reporting window is 1 to 30 September 2026.

The EU Cyber Resilience Act requires manufacturers to keep an SBOM and to handle the known vulnerabilities in their products, so your SBOM is the list to check this report against. This month the largest groups of fixes were in the U-Boot network boot code, the TLS libraries, libxml2, and Python.

We report a package issue only when it meets one of three tests. The CVSS base score is 7.0 or higher, or the issue is in the CISA KEV catalog, or it is clearly reachable in a normal device build. Scores come from the source named for each item. Projects, NVD and the CISA ADP do not always agree, and we say so where the gap is large. We leave out disputed issues and issues that need unusual build options. Kernel CVEs are not here. The weekly kernel advisory covers them.

Open-source device CVEs to update this month

Package CVE(s) / advisory Bug type Fixed version Verticals
U-Boot CVE-2026-15390, CVE-2026-74220, CVE-2026-74221, CVE-2026-74222, CVE-2026-71971, CVE-2026-74225, CVE-2026-71972, CVE-2026-71973 Network boot parsing flaws: IP fragment reassembly (9.0 and 8.2), NFS READ and READLINK replies (8.2), a use-after-free in the lwIP wget client (8.2), DHCPv6 options (7.1). Two boot-time image parsers (BMP and SquashFS, 5.9 and 5.2) are listed for reachability only. See the note on scoring below the table 2026.10-rc5 or later clears all but two. Final 2026.10 is not tagged yet. CVE-2026-15390 and CVE-2026-71972: commits only Embedded/IoT, Mobile/Automotive, Medical
OpenSSL CVE-2026-84782 DTLS retransmit reads from the wrong buffer offset: heap disclosure or crash (project severity High) 4.0.3, 3.6.5, 3.5.9, 3.4.8. 3.0.23 is for premium support customers only Mobile/Automotive, Embedded/IoT, Cloud/Datacenter, Medical
wolfSSL CVE-2026-93302, CVE-2026-89102, CVE-2026-89136 Certificate and authentication checks that can be bypassed: trusted-peer match ignores the public key, OCSP multi-stapling accepts any chain certificate, unsolicited raw public key accepted (all 8.3, project CNA) 5.9.4 Mobile/Automotive, Embedded/IoT, Medical
expat CVE-2026-93990 A lone UTF-16 high surrogate is accepted and changes the next character (7.5, integrity only) 2.8.5 Embedded/IoT, Medical
zlib CVE-2026-85091 Heap overflow in gzprintf() after a stalled non-blocking gzwrite() (7.4). Proof of concept is published No release. Fix is a commit. 1.3.2 is still the newest release and is affected Embedded/IoT
libxml2 CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144 Six integer overflow, buffer overflow and XInclude flaws in parsing and serialising XML (7.3 to 7.8 NVD, local vector) 2.15.4 Embedded/IoT, Medical
BusyBox CVE-2026-88830, CVE-2026-88832 Heap overflow in the TLS test applet ssl_server (7.5) and in romfs volume ID parsing (7.3) No upstream fix found. The newest release, 1.38.0, is affected Embedded/IoT
Python CVE-2026-19445, CVE-2026-19553, CVE-2026-82049 Use-after-free in ssl servers that switch contexts in sni_callback (9.2). Hostname check silently skipped in wrap_bio() without server_hostname (7.6). tarfile filter bypass through a hard link to a symlink (8.4). All scored by the Python CNA with CVSS 4.0 3.14.8, 3.13.16, 3.12.15, 3.11.17, 3.10.22, 3.15.0 (the tarfile issue is fixed on 3.13 and earlier only) Cloud/Datacenter, Embedded/IoT
FFmpeg CVE-2026-30754, CVE-2026-96611 Out-of-bounds write in the RTP muxer (8.8, CISA-ADP). Integer overflow in HEIF parsing (6.9, listed for reachability) 8.1 for CVE-2026-30754. 9.0 for CVE-2026-96611; an 8.x backport is not confirmed Mobile/Automotive, Medical
GStreamer CVE-2026-85150, GStreamer-SA-2026-0081, GStreamer-SA-2026-0080 RTSP Digest header NULL dereference, remote denial of service (7.5, Red Hat CNA). Out-of-bounds read and write in gst-libav audio with more than 64 channels (no CVE, no score). souphttpsrc forwards credentials on cross-origin redirects (no CVE, no score) 1.28.7 Mobile/Automotive, Medical
WebKitGTK WSA-2026-0006 One advisory bundling memory-safety and policy fixes in the web engine. The project gives no CVSS scores 2.54.0 Mobile/Automotive, Medical
Chromium CVE-2026-85046, CVE-2026-87491 In CISA KEV. Two V8 bugs, a type confusion (8.8) and an out-of-bounds write (8.8), both with active exploitation recorded by CISA Chrome 152.0.7977.82 and 153.0.8010.36 respectively Medical
containerd CVE-2026-95837 CRI checkpoint restore bypasses the destination security context (project severity Critical, no CVSS published) 2.2.7 and 2.3.4 Cloud/Datacenter
BlueZ CVE-2026-85218, CVE-2026-19774 AVRCP stack overflow, adjacent radio range, user action needed (7.3). A2DP stream endpoint stack overflow, needs pairing (7.1). Both run in a root daemon No release. Commits only. 5.87 is the newest tag and is affected by the AVRCP issue Mobile/Automotive, Embedded/IoT, Medical

A note on scoring. The U-Boot scores for CVE-2026-74220, CVE-2026-74221, CVE-2026-74222, CVE-2026-71971 and CVE-2026-74225 come from the VulnCheck CNA, which also published the CVEs on 29 September. CISA adds only exploitation and automation labels to them. The CVE-2026-15390 score of 9.0 comes from the CERT-PL CNA. Its record says the fix is in version 2026.07 and also lists 2026.07 as affected. Those two statements conflict, so take the fix commit b1aec609 and do not rely on the version number. The Python scores use CVSS 4.0 only, which tends to give higher numbers than CVSS 3.1 for the same flaw. The GStreamer score is from Red Hat, and the GStreamer project itself says the flaw cannot cause code execution.

The OpenSSL advisory of 29 September also lists CVE-2026-84783, a use-after-free in the X.509 extension cache. The project rates it Moderate and it affects OpenSSL 4.0 only. Update to 4.0.3 if you run 4.0. Other OpenSSL items in that advisory are rated Low, mostly in QUIC and in timing side channels. Check them only if your devices use QUIC or DTLS with the affected features.

Other items we reviewed and left out of the table. CVE-2026-19499 in glibc (strfmon, 7.7 from the glibc CNA) needs an application that passes an attacker-controlled format to strfmon, the CVE text says no network-facing impact is known, and we could not confirm the fixed release. CVE-2026-78807 in wpa_supplicant (7.1 from the CISA ADP) is local only, and we could not confirm a fixed version. An xz advisory, GHSA-5qpq-xqfv-j9pg, fixed in 5.8.4, needs an unusual memory-allocation failure and affects only the .lzma and .lz formats. The containerd release also fixed three Moderate denial-of-service issues (CVE-2026-53495, CVE-2026-95838, CVE-2026-53493). Two Mbed TLS CVEs published in September (CVE-2026-25832 and CVE-2026-73064) belong to July advisories and score 3.7 and 2.9.

Packages checked this month with nothing that met the tests: GnuTLS, OpenSSH, Dropbear, SQLite, curl, systemd, dnsmasq, NetworkManager, runc, Node.js, OpenJDK and Mesa. Mbed TLS had no advisory dated September. For curl, the nine CVEs listed on 2 September are all rated Low by the project except one Medium, so none is in the table, although the CISA ADP gives CVE-2026-82208 a 7.5. For these packages: D-Bus, GRUB2, musl, ConnMan, Avahi and Trusted Firmware-A, we checked the Debian tracker and the CVE records, and for some we also checked the project index. Two Trusted Firmware-A advisories, TFV-14 and TFV-15, had no public CVE record or publication date when we checked. Treat those six packages as a weaker negative than the others.

Carried over from earlier months

Several items were also flagged last month and are still open. BlueZ has published no release since 5.87. The LE Audio advisory GHSA-9683-2chf-hfw9 and the BASS advisory GHSA-7wjj-8mrm-jhw4 still show no patched version, and the August fixes for CVE-2026-80186 and CVE-2026-80185 are still commits only. The patch table in this post is the authoritative one for BlueZ.

Last month we named U-Boot 2026.07 as the practical baseline. This month's network-boot fixes landed in 2026.10-rc3 to 2026.10-rc5, so 2026.07 no longer clears the month. FFmpeg 8.1.3 was released on 21 September. We could not confirm from a tag whether it contains the July fixes, so check its release notes. BusyBox CVE-2026-38752 to CVE-2026-38755 still have no fixed release. The SQLite use-after-free CVE we mentioned in July, CVE-2026-51290, was rejected by its CNA on 31 July as not a security issue.

Mobile and automotive

On automotive SoCs that ship U-Boot, it runs first in the boot chain. This month the issues are in the network boot path. CVE-2026-15390 is an out-of-bounds write in IP fragment reassembly. It needs CONFIG_IP_DEFRAG=y and an attacker on the same network segment. CVE-2026-74220 and CVE-2026-74221 are in NFS reply handling, CVE-2026-74222 is in the wget client, and CVE-2026-74225 is in DHCPv6. All of them need a network boot feature to be enabled and an attacker who controls or imitates a boot server. If your production boot flow does not use network boot, the risk is low. Update to 2026.10-rc5 or later, or cherry-pick the fix commits.

Bluetooth is the exposed surface in a vehicle, because the head unit pairs with phones the manufacturer does not control. CVE-2026-85218 is a stack overflow in the BlueZ AVRCP controller code. A nearby device can trigger it, and the user must take part in the connection. CVE-2026-19774 is a stack overflow in the A2DP stream endpoint code and needs the attacker to pair first. Both run in bluetoothd, which runs as root. There is no BlueZ release to move to. Use your distribution's patched package or cherry-pick the commits. Debian reports 5.87-4 as carrying the A2DP fix.

In the media pipeline, CVE-2026-85150 lets a remote peer crash a GStreamer RTSP server that has authentication enabled, or an RTSP client that talks to a malicious server. Advisory GStreamer-SA-2026-0081 covers gst-libav: media with more than 64 audio channels writes outside the channel arrays. Update to 1.28.7 for both. For FFmpeg, CVE-2026-30754 affects the RTP muxer only, so it matters if the device sends RTP streams built from untrusted input. Update to 8.1 or later. CVE-2026-96611 parses HEIF and MOV images, so it is reachable from untrusted files. It is fixed in 9.0.

For OpenSSL, CVE-2026-84782 matters if your telematics or connectivity stack uses DTLS. It needs a write that is suspended partway through a handshake. Update to 3.6.5, 3.5.9 or the release for your branch. For wolfSSL, the three CVEs affect certificate and authentication checks. Update to 5.9.4. Two of them depend on build options, so check your configuration. WebKitGTK 2.54.0 fixes the engine issues in advisory WSA-2026-0006. Update it if your head unit renders web content.

Embedded and IoT

On small devices, the bootloader, the TLS library and the parsers handle untrusted input. For U-Boot, update to 2026.10-rc5 or later if the device uses network boot, DHCPv6 or a wget client, or mounts media a user can replace. The two lower-scored issues, CVE-2026-71972 (BMP splash images) and CVE-2026-71973 (SquashFS), matter only if the device parses an image from storage that an attacker can replace.

For TLS, update OpenSSL for CVE-2026-84782 if the device uses DTLS, and update wolfSSL to 5.9.4. The wolfSSL issue CVE-2026-89136 affects only builds with raw public key support. That option is off by default but it is enabled by the --enable-all and --enable-distro configurations. CVE-2026-93302 affects builds that define WOLFSSL_TRUST_PEER_CERT.

Update expat to 2.8.5 and libxml2 to 2.15.4. The libxml2 flaws are scored with a local vector, so the risk depends on whether your application parses XML that comes from outside. The zlib flaw has no release. It affects only code that calls gzprintf() on a non-blocking write stream. Check whether your code does that, and apply the upstream commit if it does.

BusyBox has no upstream fix for either item. CVE-2026-88830 is in the ssl_server applet, which Red Hat describes as a test and debug tool that is not shipped in its package. Check whether your BusyBox build enables it. CVE-2026-88832 needs a crafted romfs image to be mounted. If you run Python on the device, update it for the tarfile issue CVE-2026-82049 when you extract archives from outside, for example update bundles. Update BlueZ using the commits as described above if the device uses Bluetooth.

Cloud and datacenter

For OpenSSL, CVE-2026-84782 applies to any DTLS endpoint. Update to 3.6.5, 3.5.9 or 3.4.8. If you run OpenSSL 3.0 outside a premium support contract, ask your distribution for a backport. For OpenSSL 4.0, also update for CVE-2026-84783.

Python has the largest set. CVE-2026-19445 lets a remote client crash an ssl server, or call through a freed pointer, if its sni_callback swaps the context and nothing else keeps the original context alive. Servers that wrap only the listening socket are not affected, and TLS clients are not affected. CVE-2026-19553 is the opposite case for clients: wrap_bio(), asyncio.create_connection() and asyncio.loop.start_tls() skip hostname checks when server_hostname is missing. The project says you can mitigate it by always passing a valid server_hostname. Update to 3.14.8, 3.13.16, 3.12.15, 3.11.17 or 3.10.22.

For containerd, CVE-2026-95837 is rated Critical by the project and affects only hosts where CRI checkpoint restore is used. Update to 2.2.7 or 2.3.4. Those versions turn restore through CreateContainer off by default. Containers that were restored from untrusted checkpoints should be stopped and recreated.

Medical devices

Connected medical devices draw their packages from the other stacks. The risk is whichever package is reachable from a network or parses untrusted clinical data. Bluetooth is the clearest case. Patient monitors, wearables and gateways use BlueZ to pair with sensors and phones. CVE-2026-85218 and CVE-2026-19774 run in a root daemon and have no tagged fix, so plan for the distribution package or the commits.

For data and media, libxml2 and expat parse XML that often carries HL7 or FHIR content, so update to 2.15.4 and 2.8.5. FFmpeg and GStreamer handle imaging and endoscopy video: update FFmpeg to 8.1 or later and GStreamer to 1.28.7. For device touchscreen interfaces, update WebKitGTK to 2.54.0 and Chromium to the fixed builds. The two Chromium V8 issues are in the CISA KEV catalog, so a device that browses untrusted content has the highest priority here. For TLS, update OpenSSL and wolfSSL as listed in the table. For U-Boot, the network boot issues matter only where the service flow uses network boot.

Medical-device updates go through validation and regulatory change control, including US FDA postmarket cybersecurity guidance, EU MDR and IEC 62304. The action is to schedule these updates through the device manufacturer's change-control process, and not to patch a deployed device in place.

How to check if it applies to you

Three questions decide whether a row is your problem. First, is the package in your image and your SBOM? If it is not built into the product, its CVEs are not yours. Second, is the vulnerable feature built or enabled? Examples are CONFIG_IP_DEFRAG in U-Boot, WOLFSSL_TRUST_PEER_CERT in wolfSSL, and the ssl_server applet in BusyBox. Third, is your version below the fixed version? Distributions often backport a fix without changing the upstream version number, so check your distribution changelog before you assume you are exposed. For packages with only a commit, compare the source tree with the commit instead of a version. These commands read two versions on a running device:

raghu@techveda.org:~$ openssl version
OpenSSL 3.5.8
raghu@techveda.org:~$ python3 --version
Python 3.13.15
Enter fullscreen mode Exit fullscreen mode

In this example, OpenSSL 3.5.8 is below the fixed 3.5.9, and Python 3.13.15 is below the fixed 3.13.16. Both updates apply, if the affected feature is in use. The output above is shortened and is an example, not a measured result.

Key takeaways

  • September 2026 has 36 device-stack CVEs and advisories across 14 packages. Two are in the CISA KEV catalog, and both are Chromium V8 bugs.
  • U-Boot has the largest group. Its network boot fixes are in 2026.10-rc5 or later, so the 2026.07 baseline we gave last month is no longer enough.
  • BlueZ still has no release after 5.87. Use your distribution package or cherry-pick the commits.
  • Check the build options. Several wolfSSL, U-Boot and BusyBox items apply only to specific configurations.
  • Python and OpenSSL have new fixed releases on every maintained branch. Update them and rebuild.
  • Some scores come from one scorer only. Use reachability to set your priority order, and do not rely on the number alone.
  • Map each CVE to your SBOM, confirm the feature is built and your version is below the fix, then update the package and rebuild the image.

Frequently asked questions

What are open-source device CVEs?
They are security vulnerabilities in the open-source packages that ship inside a device image, such as the bootloader, the TLS libraries, the media pipeline, the language runtimes and the container runtime. This roundup covers that device stack and leaves the Linux kernel to a separate weekly report.

Are any of these being exploited right now?
Two of them are. CVE-2026-85046 and CVE-2026-87491 are Chromium V8 bugs that CISA added to the Known Exploited Vulnerabilities catalog on 4 and 9 September 2026. No other package in this roundup is in the catalog. A proof of concept is published for the zlib issue CVE-2026-85091, and we found no evidence of exploitation of it. Most items have a fix upstream, so the action is to schedule the update.

There is no BlueZ release with the fixes. What do I do?
Take your Linux distribution's patched BlueZ package, or cherry-pick the fix commits into your build. The newest upstream tag is 5.87, and it is affected by the AVRCP issue CVE-2026-85218. Moving to the newest tag does not clear the month.

Why does last month's U-Boot advice not cover this month?
Last month we named U-Boot 2026.07 as the practical baseline. The network boot issues published on 29 September were fixed in 2026.10-rc3 to 2026.10-rc5, so 2026.07 does not include those fixes. Update to 2026.10-rc5 or later, or cherry-pick the commits.

Do I need to patch every package in the table?
No. Patch the packages that are in your image and your SBOM, whose vulnerable feature is built or enabled, and whose version is below the fixed version. The three checks in the section above narrow the table to the rows that affect your product.

How does this relate to the Cyber Resilience Act and the SBOM?
The Cyber Resilience Act expects a manufacturer to keep an SBOM and to handle the known vulnerabilities in the product. Your SBOM is the list you compare this report against. That turns a general CVE feed into a short, specific set of updates for your image.

Further reading

Top comments (0)