CVE 8.2 HIGH

CVE-2026-46728_CVE-2026-46728

8.2 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

Basic Information

ID CVE-2026-46728
Source mitre
Published May 16, 2026 at 21:26

Affected Product

Vendor denx
Product U-Boot
Affected Versions denx U-Boot 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.