U-Boot NFS client
Independently found a pre-auth buffer overflow in U-Boot's NFS client — pointer hijack, NFS state-machine takeover, shellcode delivery, full chain and public PoC. It collided with a private report filed a month earlier, so the CVE went to the other reporter.
Patches are upstream, including a second negative-length bug in nfs_read_reply() found on the way.