logo

Multiple U-Boot Vulnerabilities Enable Pre-Authentication Code Execution and Device DoS Attacks

ID: fe651f80-1b07-563e-82ab-16eab361c439

STIX ID: report--fe651f80-1b07-563e-82ab-16eab361c439

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Divya

...
...

Six critical vulnerabilities in U-Boot's FIT image parsing and verified-boot implementation (BRLY-2026-037 to BRLY-2026-042) allow attackers to trigger pre-authentication arbitrary code execution (via chained stack corruption) or denial-of-service (NULL dereferences, OOB reads, recursion/stack exhaustion) against embedded devices and BMCs; Binarly disclosed and upstream patches have been merged, and vendors are urged to backport and deploy fixes promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.