Security Advisory (Was: Re: v2026.08.1 and v2026.04.2)
Ahmad Fatoum
a.fatoum at pengutronix.de
Wed Sep 16 06:57:46 PDT 2026
On 9/16/26 15:17, Sascha Hauer wrote:
> Along with barebox-2026.09.0 we also have two stable releases with the
> FIT image vulnerabilities mentioned in the v2026.09.0 announcement
> fixed.
>
> Users using FIT image based secure boot are urged to update to one of
> these versions.
>
> A Github security advisory is currently under review and a CVE has been
> requested. I'll keep you noticed once both are available.
We're still waiting on the CVE, but the advisory is published here:
https://github.com/barebox/barebox/security/advisories/GHSA-jhvm-7xq8-rvgm
We strongly recommend updating if you depend on barebox to verify
FIT signatures.
Ahmad
>
> Sascha
>
--
Pengutronix e.K. | |
Steuerwalder Str. 21 | http://www.pengutronix.de/ |
31137 Hildesheim, Germany | Phone: +49-5121-206917-0 |
Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |
More information about the barebox
mailing list