CVE Published: 21/03/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: talos |
Vendor: n/a |
Product: Das U-Boot Status : PUBLISHED
CVE-2018-3968 Description
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot\'s verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.