CVE-2020-10648: Denx U-Boot
High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
Affected products
- Denx U-Boot: before 2018.03 (fixed in 2018.03); version 2020.01 only
- Opensuse Leap: version 15.2 only
Published 2020-03-19. Last modified 2026-06-17.