New U-Boot flaws could enable stealthy firmware attacks
ID: 0edff02d-42bb-505c-8950-4687e28d35c1
STIX ID: report--0edff02d-42bb-505c-8950-4687e28d35c1
Feed Name: Bleeping Computer
Binarly disclosed six vulnerabilities in U-Boot's FIT signature verification code that can lead to crashes and, in two cases, arbitrary code execution during the boot process; the flaws affect many releases (dating back to 2013.07) and thus numerous embedded devices (BMCs, networking gear, IoT, industrial systems). Exploitation could allow pre-OS compromise, persistent firmware malware, or disabled firmware protections; patches were submitted upstream but device vendors must incorporate fixes into firmware updates, leaving older or unsupported devices at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
