Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-2347
HistorySep 23, 2022 - 12:00 a.m.

CVE-2022-2347

2022-09-2300:00:00
ubuntu.com
ubuntu.com
19
uboot
usb
dfu
length field
security vulnerability
debian

7.7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

29.5%

There exists an unchecked length field in UBoot. The U-Boot DFU
implementation does not bound the length field in USB DFU download setup
packets, and it does not verify that the transfer direction corresponds to
the specified command. Consequently, if a physical attacker crafts a USB
DFU download setup packet with a wLength greater than 4096 bytes, they
can write beyond the heap-allocated request buffer.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchu-boot< 2020.10+dfsg-1ubuntu0~18.04.3UNKNOWN
ubuntu20.04noarchu-boot< 2021.01+dfsg-3ubuntu0~20.04.5UNKNOWN
ubuntu22.04noarchu-boot< 2022.01+dfsg-2ubuntu2.3UNKNOWN
ubuntu22.10noarchu-boot< 2022.07+dfsg-1ubuntu4.2UNKNOWN
ubuntu23.04noarchu-boot< 2022.07+dfsg-1ubuntu7UNKNOWN
ubuntu23.10noarchu-boot< 2022.07+dfsg-1ubuntu7UNKNOWN
ubuntu24.04noarchu-boot< 2022.07+dfsg-1ubuntu7UNKNOWN
ubuntu16.04noarchu-boot< anyUNKNOWN
ubuntu22.04noarchu-boot-nezha< 2022.04+git20220405.7446a472-0ubuntu0.4UNKNOWN
ubuntu23.04noarchu-boot-nezha< 2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2UNKNOWN
Rows per page:
1-10 of 121

7.7 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

29.5%