Buildroot is a lightweight, widely embedded build system and root filesystem generator used across embedded Linux devices, IoT appliances, and custom distributions, giving its vulnerabilities outsized relevance despite a narrow product scope. Its durable vulnerability signal centers on supply-chain integrity: the recurring weakness class involves downloads of code or components without cryptographic verification or source integrity checks, a structural concern that can propagate across every downstream device that uses a compromised build artifact. Defenders relying on Buildroot should prioritize source-integrity verification and monitor build-system advisories closely; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buildroot over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45838HIGH Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the | Dec 5, 2023 | 8.1 | 25 | NO | NO |
CVE-2023-45839HIGH Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the | Dec 5, 2023 | 8.1 | 24 | NO | NO |
CVE-2023-45842HIGH Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the | Dec 5, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-43608HIGH A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can | Dec 5, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-45841HIGH Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the | Dec 5, 2023 | 8.1 | 22 | NO | NO |
CVE-2023-45840HIGH Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the | Dec 5, 2023 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buildroot.
Media articles that mention a CVE ID that affects a product developed by Buildroot — matched by CVE ID, not by vendor name.