CVE-2026-33243 identifies a high-severity signature verification bypass in the barebox bootloader, affecting versions from 2016.03.0 up to 2026.03.1 (and backported to 2025.09.3). This vulnerability allows an attacker to manipulate the 'hashed-nodes' property within a FIT signature, tricking the bootloader into loading unverified or malicious images. Rated 8.2 HIGH (CVSS:3.1), exploitation requires high privileges and local access, but has low attack complexity, potentially leading to complete system compromise. While the issue has been patched, there is currently no public exploit code available, it is not listed on the CISA KEV catalog, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2013.07, < 2026.04CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | ||
2026.04CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2026.04:rc1:*:*:*:*:*:* | ||
2026.04CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2026.04:rc2:*:*:*:*:*:* | ||
2026.04CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2026.04:rc3:*:*:*:*:*:* | ||
>= 2016.03.0, < 2025.09.3CPE matchmatch criteria | cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.