CVE-2026-46728
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD
Description
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Affected (3)
Products: Denx: U Boot · Pengutronix: Barebox
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2016.03.0 to 2025.09.3 |
References (2)
Source: cve@mitre.org
Vendor AdvisoryExploitPatch
Source: cve@mitre.org
Patch
Timeline
No history available yet.