{"id":"CVE-2018-3968","details":"An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.","modified":"2026-07-08T16:40:56.682989Z","published":"2019-03-21T17:29:00.493Z","references":[{"type":"EVIDENCE","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2018-0633"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/u-boot/u-boot","events":[{"introduced":"62c175fbb8a0f9a926c88294ea9f7e88eb898f6c"},{"last_affected":"524123a70761110c5cf3ccc5f52f6d4da071b959"},{"introduced":"216a793cc1702227fd4ad624080f585038d1fa45"},{"last_affected":"0116f40bbc269c57566d69e0db8cb9da2e194d33"}],"database_specific":{"cpe":["cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*","cpe:2.3:a:denx:u-boot:2013.07:rc1:*:*:*:*:*:*","cpe:2.3:a:denx:u-boot:2013.07:rc2:*:*:*:*:*:*","cpe:2.3:a:denx:u-boot:2013.07:rc3:*:*:*:*:*:*","cpe:2.3:a:denx:u-boot:2014.07:rc1:*:*:*:*:*:*","cpe:2.3:a:denx:u-boot:2014.07:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2013.07"},{"last_affected":"2014.07"},{"introduced":"2013.07-rc1"},{"last_affected":"2013.07-rc1"},{"introduced":"2013.07-rc2"},{"last_affected":"2013.07-rc2"},{"introduced":"2013.07-rc3"},{"last_affected":"2013.07-rc3"},{"introduced":"2014.07-rc1"},{"last_affected":"2014.07-rc1"},{"introduced":"2014.07-rc2"},{"last_affected":"2014.07-rc2"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2013.07-rc1","2013.07-rc2","2013.07-rc3","2014.07-rc1","2014.07-rc2","v2014.07","v2014.07-rc4","v2014.07-rc3","v2014.07-rc2","v2014.07-rc1","v2014.04","v2014.01-rc1","v2013.10","v2013.10-rc4","v2013.10-rc3","v2013.10-rc2","v2013.10-rc1","v2013.07"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-3968.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}