Multiple U-Boot Vulnerabilities Enable Pre-Authentication Code Execution and Device DoS Attacks
ID: fe651f80-1b07-563e-82ab-16eab361c439
STIX ID: report--fe651f80-1b07-563e-82ab-16eab361c439
Feed Name: GBHackers
Threat Score
Six critical vulnerabilities in U-Boot's FIT image parsing and verified-boot implementation (BRLY-2026-037 to BRLY-2026-042) allow attackers to trigger pre-authentication arbitrary code execution (via chained stack corruption) or denial-of-service (NULL dereferences, OOB reads, recursion/stack exhaustion) against embedded devices and BMCs; Binarly disclosed and upstream patches have been merged, and vendors are urged to backport and deploy fixes promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
