8.8
CVE-2026-46728
- EPSS 0.16%
- Veröffentlicht 16.05.2026 21:26:49
- Zuletzt bearbeitet 14.07.2026 18:22:26
- CVE-Watchlists
- Unerledigt
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pengutronix ≫ Barebox Version >= 2016.03.0 < 2025.09.3
Pengutronix ≫ Barebox Version >= 2025.10.0 < 2026.03.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.055 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| MITRE | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241
https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4