logo

Critical U-Boot Bugs Undermine Secure Boot on Millions of Devices

ID: fb876091-b5b0-5cd7-aec4-83098b0bbf7d

STIX ID: report--fb876091-b5b0-5cd7-aec4-83098b0bbf7d

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-07-11

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Binarly disclosed six critical vulnerabilities in U-Boot's FIT image verification: two permit arbitrary code execution during boot, four enable denial-of-service, and the flaws trace back to code present since v2013.07, potentially affecting millions of embedded devices (routers, cameras, BMCs, etc.). Proof-of-concept images and reproduction steps are provided, upstream patches have been merged, and organizations are urged to apply firmware updates because network-based firmware update paths can enable remote exploitation without physical access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.