THREATOPS
THREAT OPSThreat News › Unfit to Boot: Breaking U-Boot's FIT Signature Verification

Unfit to Boot: Breaking U-Boot's FIT Signature Verification

lowbinarlyPublished 2026-07-09

The Binarly Research team has identified six new security vulnerabilities within U-Boot’s FIT (Flattened Image Tree) Signature Verification mechanism, a critical component for maintaining the Root of Trust in firmware. These flaws, affecting stable releases dating back to v2013.07, range from denial-of-service (DoS) conditions to potential arbitrary code execution during the processing of untruste

MITRE ATT&CK techniques

Original source: https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification