SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to Ask
Connor Glosner, Aravind Machiry
Abstract
Bootloaders are present in every device, from IoT and edge devices to datacenter servers, making them critical to system security. Modern platforms establish hardware root of trust via vendor-specific mechanisms such as CPU microcode and authenticated code modules before bootloader execution. This SoK focuses on the software boot chain that follows that hardware-rooted integrity handoff. Prior work has focused on subsets of bootloaders, often using inconsistent terminology, leaving gaps in understanding their structure and interactions.
We analyze 43 bootloaders and categorize them into three types based on their architecture and role in the boot process. We define attack surfaces for each type using our open-source dataset, BOOTBENCH, which includes 3,658 vulnerabilities and associated commits. Leveraging BOOTBENCH, we evaluate existing vulnerability detection techniques and highlight open problems, and examine limitations in defensive techniques for hardening bootloaders.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dbc0aa49-25ee-48d7-b782-e6d567b11bbeBuilds on21
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon et al.NDSS 2018 · 202 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
Related papers
- BootStomp: On the Security of Bootloaders in Mobile DevicesNilo Redini, Aravind Machiry, Dipanjan Das, Yanick Fratantonio et al.USENIX Security 2017 · 66 citations
- A Comprehensive Memory Safety Analysis of BootloadersJianqiang Wang, Meng Wang, Qinying Wang, Nils Langius et al.NDSS 2025
- Anchors that Don't Lift: Understanding Supply Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO DevicesRitwik Badola, Rajdeep Ghosh, Ashita Gupta, Chester Rebeiro et al.USENIX Security 2026
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell LibrariesKolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos et al.S&P 2026
