The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.
History

Thu, 20 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Secure Boot Bypass via Init Table Parsing in Ingenic T41/T32/T40/A1 SoCs
Weaknesses CWE-287

Thu, 20 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Secure Boot Bypass via Erroneous Init Table Order in Ingenic T41/T32/T40/A1 SoCs
Weaknesses CWE-287

Wed, 19 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Secure Boot Bypass via Erroneous Init Table Order in Ingenic T41/T32/T40/A1 SoCs
Weaknesses CWE-287

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-19T13:47:58.178Z

Reserved: 2026-06-05T00:00:00.000Z

Link: CVE-2026-50719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:31.977

Modified: 2026-08-19T14:17:31.977

Link: CVE-2026-50719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T07:30:03Z