8.8

CVE-2026-46728

Exploit
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Denx ≫ U-boot Version >= 2013.07 < 2026.04
Denx ≫ U-boot Version 2026.04 Update rc1
Denx ≫ U-boot Version 2026.04 Update rc2
Denx ≫ U-boot Version 2026.04 Update rc3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
MITRE 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241
Patch
https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
Patch
Vendor Advisory
Exploit