VYPR
High severity8.2NVD Advisory· Published May 16, 2026· Updated Sep 11, 2026

CVE-2026-46728

CVE-2026-46728

Description

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • U Boot/U Bootllm-fuzzy2 versions
    <2026.04+ 1 more
    • (no CPE)range: <2026.04
    • (no CPE)
  • Barebox/Bareboxllm-fuzzy
  • cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
    Range: >=2013.07,<=2025.10
  • cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:*
    Range: >=2016.03.0,<2025.09.3

Patches

Vulnerability mechanics

References

2

News mentions

1