THREAT OPS › Threat News › [NVD] CVE-2026-33243 (HIGH 8.2) — barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were ve
[NVD] CVE-2026-33243 (HIGH 8.2) — barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were ve
CVE-2026-33243 CVSS: 8.2 HIGH Published: 2026-03-20T23:16:47.167
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) s
Indicators of compromise
- CVE-2026-33243cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33243