Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
ID: e0542d04-412b-5774-9ab2-3b39065aa7a9
STIX ID: report--e0542d04-412b-5774-9ab2-3b39065aa7a9
Feed Name: The Hacker News
Binarly researchers disclosed six vulnerabilities in the U-Boot bootloader affecting many devices that use FIT images; two of the flaws can enable attacker-controlled code execution during early boot (undermining chain-of-trust) and four lead to crashes. PoC images and reproduction steps were published, no in-the-wild exploitation has been reported, and upstream patches were merged but fixes may not yet be present in vendor firmware — vendors should pull the commits and push firmware updates to affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
