Aller au contenu

Fiche vulnérabilité

CVE-2026-46728 : faille élevée denx u-boot (CVSS 8.8)

Description

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
16 mai 2026
Dernière mise à jour
11 sept. 2026

Produits concernés

  • denx u-boot

Références

Rechercher une autre vulnérabilité dans la base CVE