Six flaws sit in the code that checks whether firmware is genuine — and it has been there since 2013
Binarly found six vulnerabilities in U-Boot's FIT signature verification. Two allow code execution during verification itself. The code dates to U-Boot 2013.07, and the devices running it mostly update through vendors who may never ship a patch.

