<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[wolfSSL - Embedded SSL Library — wolfBoot 2.9.0 Released]]></title>
	<link rel="self" href="https://www.wolfssl.com/forums/feed-atom-topic2556.xml" />
	<updated>2026-07-22T17:31:53Z</updated>
	<generator>PunBB</generator>
	<id>https://www.wolfssl.com/forums/topic2556-wolfboot-290-released.html</id>
		<entry>
			<title type="html"><![CDATA[wolfBoot 2.9.0 Released]]></title>
			<link rel="alternate" href="https://www.wolfssl.com/forums/post8882.html#p8882" />
			<content type="html"><![CDATA[<p>The wolfSSL team is pleased to announce <a href="https://www.wolfssl.com/products/wolfboot/">wolfBoot 2.9.0</a>, expanding hardware support, adding new image and cryptographic options, and continuing security hardening across boot and update flows.</p><p><span class="bbu"><strong>More Hardware Targets</strong></span><br />wolfBoot 2.9.0 adds support for several new platforms, including:</p><ul><li><p>STM32N6, STM32U3, STM32C5, STM32G4 and STM32WBA</p></li></ul><ul><li><p>NXP LPC54S018M-EVK and Kinetis KL26</p></li></ul><ul><li><p>Xilinx Zynq-7000 ZC702</p></li></ul><ul><li><p>NXP T2080 and CW VPX3-152 with VxWorks 7 64-bit boot support</p></li></ul><p>Existing ports also received significant updates. wolfHAL is now integrated into wolfBoot, with an STM32WB example, while STM32H5 gains firmware TPM support in TrustZone and a wolfHSM-backed TrustZone engine.</p><p>Additional improvements include hardware cryptography on LPC55S69, hardware-based DICE attestation on NXP MCXN, enhanced PolarFire SoC M-mode support, improved ZynqMP Linux boot, and fixes for Vorago VA416x0 shadow updates.</p><p><span class="bbu"><strong>New Features</strong></span><br />wolfBoot 2.9.0 adds <strong>RSA-PSS image signatures</strong> and a generic crypto-callback interface for hardware-accelerated cryptography.</p><p>FIT image support has been extended to handle gzip-compressed kernels and ramdisks, including initramfs, as well as FPGA bitstreams.</p><p>The release also introduces:<br /></p><ul><li><p>Boot benchmarking</p></li></ul><ul><li><p>One-shot hashing</p></li></ul><ul><li><p>Monolithic self-update optimizations</p></li></ul><ul><li><p>Multi-root-CA verification and keystore-less operation with wolfHSM</p></li></ul><ul><li><p>Pre-computed IDevID authentication values</p></li></ul><ul><li><p>Persistent boot and update failure diagnostics</p></li></ul><ul><li><p>An sbom Makefile target generating CycloneDX and SPDX output for software-transparency and CRA-readiness workflows</p></li></ul><p><span class="bbu"><strong>Security Hardening</strong></span><br />This release continues Fenrir fuzzing-driven hardening across image parsing and update paths.</p><p>New checks bound unauthenticated image sizes before loading them into RAM, enforce memory-copy limits during disk updates, and strengthen image authenticity and integrity verification against fault injection.</p><p>The release also fixes several LMS, XMSS, OTP keystore, device-tree, self-update and unit-test issues, while ensuring sensitive DICE claim data is zeroized after use.</p><p><span class="bbu"><strong>Download it now</strong></span><br />wolfBoot 2.9.0 is available on our <a href="https://www.wolfssl.com/download/">download page</a> and on <a href="https://github.com/wolfssl/wolfboot">GitHub</a>, bringing broader platform coverage, stronger hardware integration and continued improvements to secure firmware verification and update reliability.</p><p>If you have questions about any of the above, please contact us at <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></content>
			<author>
				<name><![CDATA[shizuka]]></name>
				<uri>https://www.wolfssl.com/forums/user5631.html</uri>
			</author>
			<updated>2026-07-22T17:31:53Z</updated>
			<id>https://www.wolfssl.com/forums/post8882.html#p8882</id>
		</entry>
</feed>
