CVE-2026-33243

HIGH EPSS 1.4%
Published Mar 20, 20263mo ago · Modified Jun 17, 20261w ago
8.2 CVSS 3.1
High
Find Similar
Published Mar 20, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and could therefore be modified to allow booting different images than those that have been verified. This issue has been patched in barebox versions 2026.03.1 and backported to 2025.09.3.

CVSS Details

Base Score
8.2
Exploitability
1.5
Impact
6.0
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
1.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-345

Affected Products 6

VendorProductVersionRange
denxu-boot*≥2013.07  –  <2026.04
denxu-boot2026.04any
denxu-boot2026.04any
denxu-boot2026.04any
pengutronixbarebox*≥2016.03.0  –  <2025.09.3
pengutronixbarebox*≥2025.10.0  –  <2026.03.1

References 2

  • github.com https://github.com/barebox/barebox/commit/aca01795056d51060cb096f9a1ea309361743e05
    Patch
  • github.com https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
    PatchVendor Advisory

Remediation

  • github.com https://github.com/barebox/barebox/commit/aca01795056d51060cb096f9a1ea309361743e05
    Patch
  • github.com https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
    PatchVendor Advisory