← Back

CVE-2022-2347

nvd nist
Published: Sep 23, 2022Modified: May 12, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 6.0
Source: NVD

Description

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

Affected (1)

Products: Denx: U Boot
1 product
U Boot
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2012.10 to 2022.07

References (4)

Source: cve-coordination@google.com
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.