PT-2022-16011 · U-Boot+4 · U-Boot+4
Sultan Qasim Khan
·
Published
2022-02-27
·
Updated
2025-05-01
·
CVE-2022-2347
CVSS v3.1
7.7
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UBoot (affected versions not specified)
Description
The issue is related to an unchecked length field in UBoot's DFU implementation. Specifically, the U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. This allows a physical attacker to craft a USB DFU download setup packet with a
wLength greater than 4096 bytes, potentially writing beyond the heap-allocated request buffer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
U-Boot
Ubuntu