On 9/16/26 15:17, Sascha Hauer wrote: > Along with barebox-2026.09.0 we also have two stable releases with the > FIT image vulnerabilities mentioned in the v2026.09.0 announcement > fixed. > > Users using FIT image based secure boot are urged to update to one of > these versions. > > A Github security advisory is currently under review and a CVE has been > requested. I'll keep you noticed once both are available.
We're still waiting on the CVE, but the advisory is published here: https://github.com/barebox/barebox/security/advisories/GHSA-jhvm-7xq8-rvgm We strongly recommend updating if you depend on barebox to verify FIT signatures. Ahmad > > Sascha > -- Pengutronix e.K. | | Steuerwalder Str. 21 | http://www.pengutronix.de/ | 31137 Hildesheim, Germany | Phone: +49-5121-206917-0 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |
