U-Boot
Security Risk Profile
56
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 10, 2025 to present
6
Total CVEs
3
Critical+High
1
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
8.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
56/100
medium
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
0High
3Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
1
2
Integer Underflow
1
Most Affected Products
1. DENX U-Boot13
2. U-Boot U-boot5
3. U-Boot FIT (Flattened Image Tree) signature verification code1
4. DENX Universal Boot Loader (U-Boot)1
5. Qualcomm Qualcomm chips1
Recent Vulnerabilities
See more →bleepingcomputer-20260710215902
unknown
New U-Boot flaws could enable stealthy firmware attacks
7/10/2026⚠ Exploited🔧 No Patch
CVE-2026-29009
CVSS 8.8high
U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
7/8/2026🔧 No Patch
CVE-2026-29008
CVSS 8.7high
U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
7/8/2026🔧 No Patch
CVE-2026-29007
CVSS 6.9medium
U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
7/8/2026🔧 No Patch
CVE-2025-24857
CVSS 8.4high
12/10/2025
ICSA-25-343-01
unknown
8/16/2026
Monitor U-Boot in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.