Signature Verification Bypass in Das U-Boot Firmware
CVE-2026-46728

8.2HIGH

Key Information:

Vendor

Denx

Status
Vendor
CVE Published:
16 May 2026

What is CVE-2026-46728?

The Das U-Boot firmware prior to version 2026.04 is prone to a signature verification bypass that occurs due to the omission of hashed-nodes from a hash calculation. This enables an attacker to exploit the system by bypassing the expected verification process, potentially leading to unauthorized access or manipulation of boot images. Users and administrators are advised to update to the latest version to mitigate this risk. For more detailed information, refer to the official advisories.

Affected Version(s)

U-Boot 0 < 2026.04

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.