CVE-2026-46728: High severity Das U-Boot Das U-Boot vulnerability
Published May 16, 2026
·Updated
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Affected Software
4 affected components
Das U-Boot Das U-Boot<2026.04
DENX U-Boot>=2013.07<=2025.10
Pengutronix barebox>=2016.03.0<2025.09.3
Pengutronix barebox>=2025.10.0<2026.03.1
Remediation
Event History
May 16, 2026
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46728?
CVE-2026-46728 has a high severity due to its potential impact on the integrity of image verification.
2
How do I fix CVE-2026-46728?
To fix CVE-2026-46728, update Das U-Boot to version 2026.04 or later where the vulnerability is addressed.
3
What does CVE-2026-46728 affect?
CVE-2026-46728 affects Das U-Boot versions prior to 2026.04, specifically targeting the Flat Image Tree signature verification.
4
Can CVE-2026-46728 lead to unauthorized access?
Yes, CVE-2026-46728 can lead to unauthorized access by allowing a malicious user to bypass signature verification.
5
Is CVE-2026-46728 a critical vulnerability?
CVE-2026-46728 is considered critical, as it compromises the security controls in place for image verification.