CVE-2026-46728: Denx U-Boot
High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Affected products
- Denx U-Boot: from 2013.07, before 2026.04 (fixed in 2026.04); version 2026.04 only
Published 2026-05-16. Last modified 2026-09-11.