CVE-2020-10648: Denx U-Boot

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

Affected products

  • Denx U-Boot: before 2018.03 (fixed in 2018.03); version 2020.01 only
  • Opensuse Leap: version 15.2 only

Published 2020-03-19. Last modified 2026-06-17.