CVE Tools

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

The Hacker NewsBy The Hacker News

PoC publicBinarly

Our summary

Security researchers from Binarly have uncovered six critical vulnerabilities in U-Boot, a widely used bootloader for devices ranging from home routers to server management chips. Two of the flaws could allow an attacker to execute arbitrary code before the device verifies the authenticity of the software, potentially compromising the entire system. The remaining four issues can cause crashes that disrupt device operation. These bugs stem from improper validation of untrusted images during the boot process and affect versions dating back to U-Boot v2013.07. While no CVE identifiers have been assigned yet, Binarly has published proof-of-concept exploits for each flaw. Vendors are urged to apply upstream fixes immediately, as official patches are not included in the latest stable release.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store