BRLY-2026-044
Out-of-bounds write in U-Boot SPL during FIT image loading because of unchecked properties of image external data
CVE ID
BRLY-2026-044
Vendors Affected
U-Boot
Products Affected
Summary
U-Boot SPL (Secondary Program Loader) contains an out-of-bounds write vulnerability in the FIT image loading logic, allowing a potential attacker to execute arbitrary code in the context of the bootloader and bypass U-Boot Verified Boot.
Image preview
Potential Impact
An attacker can exploit this vulnerability to achieve pre-authentication code execution in the context of the bootloader, which could lead to full control over the device.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2026-044
- BINARLY calculated CVSS v3.1: 6.8 Medium AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Image preview
See if you are impacted now with our Firmware Vulnerability Scanner
Find Vulnerabilities, Generate SBOMs & CBOMs