Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Security researchers from Binarly have uncovered six critical vulnerabilities in U-Boot, a widely used bootloader for devices ranging from home routers to server management chips. Two of the flaws could allow an attacker to execute arbitrary code before the device verifies the authenticity of the software, potentially compromising the entire system. The remaining four issues can cause crashes that disrupt device operation. These bugs stem from improper validation of untrusted images during the boot process and affect versions dating back to U-Boot v2013.07. While no CVE identifiers have been assigned yet, Binarly has published proof-of-concept exploits for each flaw. Vendors are urged to apply upstream fixes immediately, as official patches are not included in the latest stable release.