An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.
Cite this page
CVE-2018-3968. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-3968
Use CWE-347, Denx vendor hub and U-Boot product page to widen CVE-2018-3968 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-33243, CVE-2024-42040 and CVE-2022-33967 for nearby disclosures in the same product family.