Logo
vulnerabilityCVE-2022-2347
Name
CVE-2022-2347
Source
NVD ( link)Debian ( link)
Description
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
u-boot
Exploitable

Vulnerability Ratings#


7.7
CVSSv31
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2021.07
Exploitable
buildroot
master
2026.04
Not Affected
yocto
master
2026.04
Not Affected
yocto
scarthgap
2024.01
Not Affected