Trusted Boot Project maintains a specialized bootloader security utility focused on establishing cryptographic verification during system startup, a narrow but structurally important role in the firmware-to-kernel transition. The durable signal centers on input-validation handling within the boot verification process, a class of flaw that reflects the complexity of parsing untrusted configuration and image data in a pre-OS environment where mitigation options are constrained; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trusted Boot Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16837HIGH Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trus | Nov 16, 2017 | 7.8 | 25 | NO | NO |
CVE-2014-5118MEDIUM Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability | Nov 18, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trusted Boot Project.
Media articles that mention a CVE ID that affects a product developed by Trusted Boot Project — matched by CVE ID, not by vendor name.