The wolfSSL team is pleased to announce wolfBoot 2.9.0, expanding hardware support, adding new image and cryptographic options, and continuing security hardening across boot and update flows.
More Hardware Targets
wolfBoot 2.9.0 adds support for several new platforms, including:
- STM32N6, STM32U3, STM32C5, STM32G4 and STM32WBA
- NXP LPC54S018M-EVK and Kinetis KL26
- Xilinx Zynq-7000 ZC702
- NXP T2080 and CW VPX3-152 with VxWorks 7 64-bit boot support
Existing ports also received significant updates. wolfHAL is now integrated into wolfBoot, with an STM32WB example, while STM32H5 gains firmware TPM support in TrustZone and a wolfHSM-backed TrustZone engine.
Additional improvements include hardware cryptography on LPC55S69, hardware-based DICE attestation on NXP MCXN, enhanced PolarFire SoC M-mode support, improved ZynqMP Linux boot, and fixes for Vorago VA416x0 shadow updates.
New Features
wolfBoot 2.9.0 adds RSA-PSS image signatures and a generic crypto-callback interface for hardware-accelerated cryptography.
FIT image support has been extended to handle gzip-compressed kernels and ramdisks, including initramfs, as well as FPGA bitstreams.
The release also introduces:
- Boot benchmarking
- One-shot hashing
- Monolithic self-update optimizations
- Multi-root-CA verification and keystore-less operation with wolfHSM
- Pre-computed IDevID authentication values
- Persistent boot and update failure diagnostics
- An sbom Makefile target generating CycloneDX and SPDX output for software-transparency and CRA-readiness workflows
Security Hardening
This release continues Fenrir fuzzing-driven hardening across image parsing and update paths.
New checks bound unauthenticated image sizes before loading them into RAM, enforce memory-copy limits during disk updates, and strengthen image authenticity and integrity verification against fault injection.
The release also fixes several LMS, XMSS, OTP keystore, device-tree, self-update and unit-test issues, while ensuring sensitive DICE claim data is zeroized after use.
Download it now
wolfBoot 2.9.0 is available on our download page and on GitHub, bringing broader platform coverage, stronger hardware integration and continued improvements to secure firmware verification and update reliability.
If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.
Download wolfSSL Now

