NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4919 most downloaded on PyPI
MCUboot's image signing and key management
Last release 10 days ago
24 Sep 2026
Release timing varies
gaps range from 2 weeks to 11 months
Most releases are documented
notes for 15 of 18 stable releases
1 version withdrawn
withdrawn after publishing
8 years old
47 releases · first in 2018
Nothing published for this version
Fixed the ext/nrf/cc310_glue include path to drop the deprecated non-zephyr/ prefix.
BOOT_SIGNATURE_TYPE_RSA no longer selects RSA key exchange support, since MCUboot only requires RSA for signature verification.MBEDTLS_VERSION_4_x Kconfig boolean in Zephyr builds to select between Mbed TLS 3.x legacy crypto and the TF-PSA-Crypto 1.x backend.TEST_RANDOM_GENERATOR in Zephyr builds when PSA crypto is enabled and no entropy driver is available, since MBEDTLS_PSA_CRYPTO_LEGACY_RNG no longer selects it implicitly.CONFIG_MBEDTLS_CFG_FILE usage to follow the rename in Zephyr.--custom-tlv-file option that works like --custom-tlv but reads the TLV value from a binary file instead of taking it on the command line.dumpinfo now supports a -f/--format option to select between human, yaml and json output. The defaults remain backwards compatible (human for stdout, yaml when writing to a file).dumpinfo can now read Intel hex (.hex) files in addition to binary files.FIXED_ prefix, allowing MCUboot to be used on devices that use fixed-partitions and zephyr,memory-mapped compatibles.DT_REG_ADDR() and DT_REG_SIZE() devicetree macros to obtain the target load area address range, allowing nodes that rely on a devicetree ranges property to be used.CONFIG_BOOT_MAX_IMG_SECTORS for Espressif targets so that auto detection can take place.ext_flash_app variant on the stm32h7s3xx, allowing chainloading applications from external flash while MCUboot runs from internal flash.zephyr,memory-mapped binding, and added missing ranges properties on a few board overlays.do_boot path so that RISC-V based Espressif SoCs no longer fall through to the wrong do_boot implementation.bootloader.conf files to reflect the default flash layout configuration for most Espressif boards on Zephyr.flash_area_get_sector to fix an undefined reference for Mbed CE.MCUBOOT_SWAP_SAVE_ENCTLV configuration option by switching to the canonical name and correcting the macro name.bootutil_public.c is built for non-bootloader builds, allowing applications to skip bootloader-only syscfgs.ih_protect_tlv_size field.MCUBOOT_SWAP_USING_MOVE. Previously, the primary region size was used, which could be larger than the secondary region, when using the optimal region sizes. Now, the size of the secondary region (excluding the swap sector and sectors needed for swapping) is used, ensuring only the valid image area is copied. This prevents potential over-copying and related issues during image upgrade or bootstrap operations.image_validate so that the offset of the swap-using-move sector is included when pure mode is used in swap-offset.image_ed25519 to no longer call mbedTLS public key functions when MCUBOOT_BUILTIN_KEY is enabled.bootutil_find_key when MCUBOOT_BYPASS_KEY_MATCH is set and MCUBOOT_HW_KEY is not.boot_serial_encryption.compatible property handling in CMake so that matching soc-nv-flash works for nodes whose compatible property contains multiple strings.. in a log message.LOG_PANIC() before jumping to the application so log backends have an opportunity to flush in-flight messages before the jump.K_NO_WAIT and is woken in zephyr_boot_log_stop() so it drains pending messages before MCUboot jumps to the application.zephyr_library_* functions where MCUboot is not actually a library.hello-world Zephyr sample, since Zephyr's tree contains a sysbuild MCUboot sample that should be used instead.ext/nrf/cc310_glue include path to drop the deprecated non-zephyr/ prefix.tsa-crypto dependency twister error.One column per quarter.
Added support for booting Cortex-R5 images
Added support for booting Cortex-R5 images
Add support for cleaning up the Cortex-R core before final jumping
Aligned the project security policy with the TrustedFirmware.org security policy.
Fixed imgtool dependency on click package version.
Enabled support for ram-load revert mode, which functions using the same logic as direct-xip revert mode but loads the executable image to ram.
Add cache flush after write/erase operations to avoid getting invalid data when these are followed by read operation.
Fix image wrong state after swap-scratch when hardware flash encryption is enabled. When hardware flash encryption is enabled, force expected erased value (0xFF) into flash when erasing a region, and also always do a real erase before writing data into flash.
Move the Virtual eFuse offset in flash configuration from hardcoded value to .conf file.
Fixed issue in boot_scramble_regions, where incorrect boundary check would cause function to attempt to write pass a designated flash area.
Fixed issue in image_validate when MCUBOOT_HASH_STORAGE_DIRECTLY is enabled
for platforms with NVM memory that does not start at 0x00.
Fixed issue in image_validate when BOOT_SIGNATURE_TYPE_PURE is enabled
for platforms with NVM memory that does not start at 0x00.
Fixed serial recovery with progressive erase for MCUboot modes of single
updatable slot (MCUBOOT_SINGLE_APPLICATION_SLOT, MCUBOOT_FIRMWARE_LOADER,
MCUBOOT_SINGLE_APPLICATION_SLOT_RAM_LOAD) which was previously failing due
to attempting to access non-existent image status fields.
Fixed issue with imgtool when trying to compress images with no header padding requested.
Fixed issue with swap using offset when mininmal erase was enabled that did not offset the erase to the second sector and wrongly used the (empty) first sector of the secondary slot.
Switched to picolibc as the default C library in Zephyr.
Fixed wrong define specifying 2 slots in single loader mode instead of just 1
Fixed wrong slot ID in hook calls from serial recovery.
Fixed issues with serial recovery not building/not working/faulting.
Swap using offset now includes the size of the unprotected TLV area which was wrongly missing before, this requires extra space in the swap status as the data is not part of the image header
Control over compilation of unprotected TLV allow list has been exposed using MCUBOOT_USE_TLV_ALLOW_LIST mcuboot configuration identifier.
Fixed issue with platforms that have MCUBOOT_SUPPORT_DEV_WITHOUT_ERASE set that did not scramble (delete) data sections from the trailer that should have been deleted.
Fixed issue with boot_scramble_region escaping flash area due to error in the range check.
A few changes to make vscode nicer, including a default package to build at the top level, and ignoring some of the cache files from vscode.
Zephyr builds are now using Kconfig CONFIG_MCUBOOT_BOOT_MAX_ALIGN to set the MCUBOOT_BOOT_MAX_ALIGN.
Fixed issue with checking pin reset not checking for single flag in Zephyr.
imgtool verify when using a public ed25519 key has been fixed to work rather than show an invalid key type not matching the TLV record error.
Zephyr signature and encryption key file path handling has now
been aligned with Zephyr, this means values can be specified in
multiple .conf file and the one that last set it will be the set
value. This also means that key files will no longer be found
relative to the .conf file and will instead be found relative
to the build system APPLICATION_CONFIG_DIR variable, though
the key file strings are now configured which allows for using
escaped CMake variables to locate the files, for example with
\${CMAKE_CURRENT_LIST_DIR} to specify a file relative to
the folder that the file is in.
Watchdog support in Zephyr has been reworked and fixed to allow installing a timeout (with a configurable value) before starting it. The default timeout is set to 1 minute and this feature has been enabled by default. 3 Kconfig options have been added which control how the watchdog is used in MCUboot:
CONFIG_BOOT_WATCHDOG_SETUP_AT_BOOT controls setting up
the watchdog in MCUboot (if not set up, it can still be set,
if the driver supports this non-compliant behaviour).CONFIG_BOOT_WATCHDOG_INSTALL_TIMEOUT_AT_BOOT controls if
a timeout is installed at bootup or not.CONFIG_BOOT_WATCHDOG_TIMEOUT_MS sets the value of the
timeout in ms.In addition, Zephyr modules can now over-ride the default
watchdog functionality by replacing the weakly defined functions
mcuboot_watchdog_setup and/or mcuboot_watchdog_feed,
these functions take no arguments.
correct esp32c6 overlay
Nothing published for this version
Nothing published for this version
Added support for retrieving HW embedded private keys for image encryption (The private key can be retrieved from trusted sources like OTP, TPM.).
thingy52, thingy53 and
nrf9160dk boards.MCUBOOT_SWAP_USING_OFFSET. This algorithm is similar to swap
using move but avoids moving the sectors in the primary slot
up by having the update image written in the second sector in
the update slot, which offers a faster update process and
requires a smaller swap status areaCONFIG_BOOT_MAX_IMG_SECTORS_AUTONothing published for this version
Nothing published for this version
Zephyr: Remove deprecated ZEPHYR_TRY_MASS_ERASE Kconfig option.
ALLOW_ROGUE_TLVSlist
to show the available tests and run to run them. The -t argument will
select specific tests to run.MCUBOOT_SKIP_SLOW_TESTS in
the environment, the sim will skip two tests that are very slow. In one
instance this reduces the test time from 2 hours to about 5 minutes. These
slow tests are useful, in that they test bad powerdown recovery, but are
inconvenient when testing other areas.CONFIG_BOOT_DISABLE_CACHES to n.CONFIG_MCUBOOT_BOOT_BANNER=n which
will revert back to the default zephyr boot banner.Nothing published for this version
Note that this release, 2.0.0 is a new major number, and contains a small API change in the interface between mcuboot and the platform. All platforms
Note that this release, 2.0.0 is a new major number, and contains a small API
change in the interface between mcuboot and the platform. All platforms
contained within the MCUboot tree have been updated, but any external platforms
will have to be adjusted. The following commit makes the API change, in the
function boot_save_shared_data.
commit 3016d00cd765e7c09a14af55fb4dcad945e4b982
Author: Jamie McCrae <jamie.mccrae@nordicsemi.no>
Date: Tue Mar 14 12:35:51 2023 +0000
bootutil: Add active slot number and max app size to shared data
Nothing published for this version
There are no security vulnerabilities reported on the MCUboot code for this release. There have been several updates to the dependencies in the Ruby c…
The 1.10.0 release of MCUboot contains...
flash_area_get_sector, along with support for each
target, that replaces flash_area_sector_from_off. This is a step in cleaning
up the flash API used by MCUboot.There are no security vulnerabilities reported on the MCUboot code for this release. There have been several updates to the dependencies in the Ruby code used to generate the documentation. This should only affect users that generate their own documentation.
Nothing published for this version
The 1.9.0 release of MCUboot contains various bug fixes, improves support on some recent targets, and adds support for devices with a write alignment
The 1.9.0 release of MCUboot contains various bug fixes, improves support on some recent targets, and adds support for devices with a write alignment larger than 8.
This change introduces a potentially incompatible change to the format
of the image trailer. If BOOT_MAX_ALIGN is kept at 8, the trailer
format does not change. However, to support larger write alignments,
this value can be increased, which will result in a different magic
number value. These targets were previously unsupported in MCUboot,
so this change should not affect any existing targets. The change has
been tested with a BOOT_MAX_ALIGN up to 32 bytes.
mimxrt685_evk boardCONFIG_BOOT_ENCRYPTION_KEY_FILE is not defined--max-align default reasonable in most cases.Nothing published for this version
Nothing published for this version
The 1.8.0 release of MCUboot contains numerous fixes, and adds support for the NuttX RTOS, and the Espressif ESP32 SDK.
The 1.8.0 release of MCUboot contains numerous fixes, and adds support for the NuttX RTOS, and the Espressif ESP32 SDK.
boot_serial changed to use cddl-gen, which removes the dependency
on tinycbor.bootutil_public library, a common interface for MCUboot
and the application.cargo test can be run from the
top level directory.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The 1.7.0 release of MCUboot adds support for the Mbed-OS platform, Equal slots (direct-xip) upgrade mode, RAM loading upgrade mode, hardening against
The 1.7.0 release of MCUboot adds support for the Mbed-OS platform, Equal slots (direct-xip) upgrade mode, RAM loading upgrade mode, hardening against hardware level fault injection and timing attacks and single image mode. There are bug fixes, and associated imgtool updates as well.
CONFIG_BOOT_WATCHDOG_FEED option.This release of MCUboot works with the Zephyr "main" at the time of the
release. It was tested as of has 7a3b253ce. This version of MCUboot also
works with the Zephyr v2.4.0, however it is recommended to enable
CONFIG_MCUBOOT_CLEANUP_ARM_CORE while using that version.
Nothing published for this version
Nothing published for this version
Nothing published for this version
CVE-2020-7595 "xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation." Fix by updating a de…
The 1.6.0 release of MCUboot adds support for the PSOC6 platform, X25519 encrypted images, rollback protection, hardware keys, and a shared boot record to communicate boot attestation information to later boot stages. There are bug fixes, and associated imgtool updates as well.
This release of MCUboot works the Zephyr "main" at the time of the release. It was tested as of has 1a89ca1238. When Zephyr v2.3.0 is released, there will be a possible 1.6.1 or similar release of Zephyr if needed to address any issues. There also may be branch releases of MCUboot specifically for the current version of Zephyr, e.g. v1.6.0-zephyr-2.2.1.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The 1.5.0 release of MCUboot adds support for encrypted images using ECIES with secp256r1 as an Elliptic Curve alternative to RSA-OAEP. A new swap met
The 1.5.0 release of MCUboot adds support for encrypted images using ECIES with secp256r1 as an Elliptic Curve alternative to RSA-OAEP. A new swap method was added which allows for upgrades without using a scratch partition. There are also lots of bug fixes, extra simulator testing coverage and some imgtool updates.
--minimal.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed CVE-2019-5477, and CVE-2019-16892. These fix issue with dependencies used in the generation of the documentation on github.
The 1.4.0 release of MCUboot primarily adds support for multi-image booting. With this release, MCUboot can manage two images that can be updated independently. With this, it also supports additions to the TLV that allow these dependencies to be specified.
Multi-image support adds backward-incompatible changes to the format of the images: specifically adding support for protected TLV entries. If multiple images and dependencies are not used, the images will be compatible with previous releases of MCUboot.
-x (or --hex_addr) flag to imgtool to set the base address
written to a hex-format image. This allows the image to be flashed
at an offset, without having to use additional tools to modify the
image.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The 1.3.1 release of MCUboot consists mostly of small bug fixes and updates. There are no breaking changes in functionality. This release should work…
The 1.3.1 release of MCUboot consists mostly of small bug fixes and updates.
There are no breaking changes in functionality. This release should work with
Mynewt 1.6.0 and up, and any Zephyr main after sha
f51e3c296040f73bca0e8fe1051d5ee63ce18e0d.
The 1.3.0 release of MCUboot brings in many fixes and updates. There are no breaking changes in functionality. Many of the changes are refactorings th…
The 1.3.0 release of MCUboot brings in many fixes and updates. There are no breaking changes in functionality. Many of the changes are refactorings that will make the code easier to maintain going forward. In addition, support has been added for encrypted images. See the docs for more information.
ptest utility to help run the simulator in different
configurations.nrf52840_pca10059. This board
supports serial recovery over USB with CDC ACM..hex
extension; otherwise saves in binary format.…functionality and imgtool utility. There are no breaking changes in MCUboot functionality, but some of the CLI parameters in imgtool were changed (eit…
The 1.2.0 release of MCUboot brings a lot of fixes/updates, where much of the changes were on the boot serial functionality and imgtool utility. There are no breaking changes in MCUboot functionality, but some of the CLI parameters in imgtool were changed (either removed or added or updated).
--slot-size was added and --pad was updated
to act as a flag parameter.--overwrite-only can be passed if not using swap upgrades--max-sectors can be used to adjust the maximum amount of sectors that
a swap can handle; this value must also be configured for the bootloader--pad-header substitutes --included-header with reverted semantics,
so it's not required for firmware built by Zephyr build systemNone
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →