HIGHCVE-2026-46728Published Modified CNA mitre
CVE-2026-46728: Das U-Boot before 2026
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Metrics
- CVSS v3.1
- 8.2
- Severity
- HIGH
- Fixed in
- 2026.04
- Affected Products
- 1
Fix available
2026.04
Affected packages
- denx / U-Boot< 2026.04 (from 0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HReferences