Signature Verification Bypass in Das U-Boot Firmware
CVE-2026-46728
8.2HIGH
What is CVE-2026-46728?
The Das U-Boot firmware prior to version 2026.04 is prone to a signature verification bypass that occurs due to the omission of hashed-nodes from a hash calculation. This enables an attacker to exploit the system by bypassing the expected verification process, potentially leading to unauthorized access or manipulation of boot images. Users and administrators are advised to update to the latest version to mitigate this risk. For more detailed information, refer to the official advisories.
Affected Version(s)
U-Boot 0 < 2026.04
