Researchers disclosed six security flaws in the widely used U-Boot bootloader that could let attackers crash devices or run malicious code before the operating system starts. Binarly identified BRLY-2026-037 through BRLY-2026-042 in U-Boot's FIT (Flattened Image Tree) signature-verification code, including two issues that may allow arbitrary code execution during firmware verification. The vulnerable code reportedly dates back to U-Boot 2013.07 and may affect more than 50 releases plus downstream vendor firmware used in BMCs, networking gear, industrial systems, and IoT devices.
Why it matters: Bootloader flaws are especially serious because they can enable stealthy, persistent malware that starts before normal security tools load. Organizations using devices with U-Boot, especially remotely updatable BMCs and embedded systems, should identify affected products and apply vendor fixes or mitigations as they become available.
Lawrence Abrams
2026.07.10
100% relevant
This article appears to be the first tracked report of Binarly's disclosure of six U-Boot FIT signature-verification vulnerabilities enabling pre-boot denial of service and possible code execution.
← Back to all stories