barebox is a bootloader. In barebox from version 2016.03.0 to before version 2025.09.3 and from version 2025.10.0 to before version 2026.03.1, when creating a FIT, mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and can therefore be modified by an attacker to trick the bootloader into booting different images than those that have been verified. This issue has been patched in barebox versions 2025.09.3 and 2026.03.1.
History

Wed, 25 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Denx
Denx u-boot
Pengutronix
Pengutronix barebox
CPEs cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2026.04:rc1:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2026.04:rc2:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2026.04:rc3:*:*:*:*:*:*
cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:*
Vendors & Products Denx
Denx u-boot
Pengutronix
Pengutronix barebox

Tue, 24 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Barebox
Barebox barebox
Vendors & Products Barebox
Barebox barebox

Fri, 20 Mar 2026 23:00:00 +0000

Type Values Removed Values Added
Description barebox is a bootloader. In barebox from version 2016.03.0 to before version 2025.09.3 and from version 2025.10.0 to before version 2026.03.1, when creating a FIT, mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and can therefore be modified by an attacker to trick the bootloader into booting different images than those that have been verified. This issue has been patched in barebox versions 2025.09.3 and 2026.03.1.
Title barebox: FIT Signature Verification Bypass Vulnerability
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-24T15:31:34.971Z

Reserved: 2026-03-18T02:42:27.509Z

Link: CVE-2026-33243

cve-icon Vulnrichment

Updated: 2026-03-24T15:31:31.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T23:16:47.167

Modified: 2026-03-25T19:26:15.717

Link: CVE-2026-33243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T21:28:14Z