CVE-2026-46728
HIGH EPSS 2.7%
Published May 16, 20261mo ago ยท Modified Jun 17, 20261w ago
8.2 CVSS 3.1
Published May 16, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago
Description
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
2.7% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-346
References 2
- github.com https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
- github.com https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.