Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
2015.04+dfsg1-2ubuntu12015.10+dfsg1-22015.10+dfsg1-32015.10+dfsg1-42016.01+dfsg1-12016.01+dfsg1-1ubuntu12016.01+dfsg1-2ubuntu12016.01+dfsg1-2ubuntu22016.01+dfsg1-2ubuntu32016.01+dfsg1-2ubuntu52016.03+dfsg1-6ubuntu22018.07~rc3+dfsg1-0ubuntu1~18.04.12018.07~rc3+dfsg1-0ubuntu2~18.04.12018.07~rc3+dfsg1-0ubuntu3~18.04.12019.07+dfsg-1ubuntu4~18.04.12020.10+dfsg-1ubuntu0~18.04.22020.10+dfsg-1ubuntu0~18.04.32019.07+dfsg-1ubuntu32019.07+dfsg-1ubuntu52019.07+dfsg-1ubuntu62020.10+dfsg-1ubuntu0~20.04.22021.01+dfsg-3ubuntu0~20.04.12021.01+dfsg-3ubuntu0~20.04.32021.01+dfsg-3ubuntu0~20.04.42021.01+dfsg-3ubuntu0~20.04.52021.01+dfsg-3ubuntu0~20.04.62021.07+dfsg-0ubuntu102021.07+dfsg-0ubuntu82021.07+dfsg-0ubuntu92022.01+dfsg-2ubuntu12022.01+dfsg-2ubuntu22022.01+dfsg-2ubuntu2.12022.01+dfsg-2ubuntu2.32022.01+dfsg-2ubuntu2.42022.01+dfsg-2ubuntu2.52022.01+dfsg-2ubuntu2.6+1 more2021.09+git20211008.62392d3-0ubuntu12022.04+git20220405.7446a472-0ubuntu0.12022.04+git20220405.7446a472-0ubuntu0.22022.04+git20220405.7446a472-0ubuntu0.32022.04+git20220405.7446a472-0ubuntu0.42023.07+dfsg-1ubuntu22024.01+dfsg-1ubuntu12024.01+dfsg-1ubuntu22024.01+dfsg-1ubuntu32024.01+dfsg-1ubuntu42024.01+dfsg-1ubuntu52024.01+dfsg-1ubuntu5.12024.01+dfsg-1ubuntu5.22025.01-0ubuntu0.24.04.12025.01-0ubuntu0.24.04.2+2 more2022.10-1089-g528ae9bc6c-0ubuntu22024.01~rc1-190-g2e89b706f5-0ubuntu12024.01~rc1-190-g2e89b706f5-0ubuntu22025.01-1~0ubuntu22025.01-3ubuntu12025.01-3ubuntu22025.01-3ubuntu42025.10-0ubuntu0.25.10.12025.01-3ubuntu42025.10-0ubuntu12025.10-0ubuntu2Exploitability
AV:LAC:LPR:HUI:NScope
S:CImpact
C:HI:HA:HCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H