HIGH🇵🇱 Wersja polska

CVE-2026-33243

CVSS 8.2v3.1pub. 2026-03-20upd. 2026-03-26

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and could therefore be modified to allow booting different images than those that have been verified. This issue has been patched in barebox versions 2026.03.1 and backported to 2025.09.3.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Denx U Boot

    APP
    Denx
    2026.042013.07 – 2026.04 (excl.)
  • Pengutronix Barebox

    APP
    Pengutronix
    2016.03.0 – 2025.09.3 (excl.)2025.10.0 – 2026.03.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-34835CRITICAL9.8PL ✓same product

Stack-based buffer overflow w Das U-Boot — komenda 'i2c md'

CVE-2022-30767CRITICAL9.8PL ✓same product

Buffer overflow w obsłudze NFS w Das U-Boot (CVE-2022-30767)

CVE-2020-13910CRITICAL9.1PL ✓same product

Barebox NFS: out-of-bounds read w net/nfs.c (nfs_read_reply)

CVE-2020-8432CRITICAL9.8PL ✓same product

Double free w U-Boot umożliwia zdalne wykonanie kodu (RCE)

CVE-2019-15938CRITICAL9.8PL ✓same product

Zdalny buffer overflow w Pengutronix Barebox — funkcja nfs_readlink_req