An integer overflow vulnerability exists in the Denx U-Boot ext4fs_get_bgdtable function, which can lead to under-allocation and arbitrary code execution. The issue was discovered in versions before 2026.04. This vulnerability affects the handling of ext4 filesystems within U-Boot, potentially allowing attackers to execute arbitrary code or cause denial-of-service conditions. The technical impact is signi [truncated]
CVE-2026-46728 is a high-severity U-Boot issue affecting FIT (Flat Image Tree) signature verification in versions before 2026.04. The supplied record says hashed-nodes is omitted from a hash, which can allow a verification bypass and weaken the integrity of signed boot images. Because this sits in the boot trust path, it deserves prompt review in any deployment that relies on U-Boot FIT signatures.