CVE-2022-2347
published 2022-09-23CVE-2022-2347: There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does…
PriorityP429high7.1CVSS 3.1
AVPACHPRNUINSCCHIHAH
EPSS
0.59%
44.5th percentile
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | u-boot | < u-boot 2023.01~rc4+dfsg-2 (bookworm) | u-boot 2023.01~rc4+dfsg-2 (bookworm) |
| denx | u-boot | >= 0 < 2021.01+dfsg-5+deb11u1 | 2021.01+dfsg-5+deb11u1 |
| denx | u-boot | >= 0 < 2023.01~rc4+dfsg-2 | 2023.01~rc4+dfsg-2 |
| denx | u-boot | >= 0 < 2023.01~rc4+dfsg-2 | 2023.01~rc4+dfsg-2 |
| denx | u-boot | >= 0 < 2023.01~rc4+dfsg-2 | 2023.01~rc4+dfsg-2 |
| denx | u-boot | >= 0 < 2020.10+dfsg-1ubuntu0~18.04.3 | 2020.10+dfsg-1ubuntu0~18.04.3 |
| denx | u-boot | >= 0 < 2021.01+dfsg-3ubuntu0~20.04.5 | 2021.01+dfsg-3ubuntu0~20.04.5 |
| denx | u-boot | >= 0 < 2022.01+dfsg-2ubuntu2.3 | 2022.01+dfsg-2ubuntu2.3 |
| denx | u-boot | 2012.10 – 2022.07 | — |
| uboot | uboot | unspecified – 2022.07 | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
osv7.1HIGH
vendor_debian7.7HIGH
vendor_ubuntu7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
u-boot-nezha vulnerability
osv·2023-11-29·CVSS 7.1
CVE-2022-2347 [HIGH] u-boot-nezha vulnerability
u-boot-nezha vulnerability
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2022-30552, CVE-2022-30790)
OSV
u-boot vulnerabilities
osv·2022-12-06·CVSS 7.1
CVE-2022-2347 [HIGH] u-boot vulnerabilities
u-boot vulnerabilities
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30552, CVE-2022-30790)
It was discovered that U-Boot incorrectly handled certain NFS lookup
replies. A remote attacker could use this issue to cause U-Boot to crash,
resulting in a denial of service,
GHSA
GHSA-57ww-qgjv-3g3c: There exists an unchecked length field in UBoot
ghsa_unreviewed·2022-09-25
CVE-2022-2347 [HIGH] CWE-122 GHSA-57ww-qgjv-3g3c: There exists an unchecked length field in UBoot
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
OSV
CVE-2022-2347: There exists an unchecked length field in UBoot
osv·2022-09-23·CVSS 7.1
CVE-2022-2347 [HIGH] CVE-2022-2347: There exists an unchecked length field in UBoot
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
Ubuntu
u-boot-nezha vulnerability
vendor_ubuntu·2023-11-29·CVSS 7.7
CVE-2022-30790 [HIGH] u-boot-nezha vulnerability
Title: u-boot-nezha vulnerability
Summary: Several security issues were fixed in u-boot-nezha.
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2022-30552, CVE-2022-30790)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
U-Boot vulnerabilities
vendor_ubuntu·2022-12-06·CVSS 7.7
CVE-2022-30767 [HIGH] U-Boot vulnerabilities
Title: U-Boot vulnerabilities
Summary: Several security issues were fixed in u-boot.
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30552, CVE-2022-30790)
It was discovered that U-Boot incorrectly handled certain NFS lookup
replies. A remote attacker could use this iss
Debian
CVE-2022-2347: u-boot - There exists an unchecked length field in UBoot. The U-Boot DFU implementation d...
vendor_debian·2022·CVSS 7.7
CVE-2022-2347 [HIGH] CVE-2022-2347: u-boot - There exists an unchecked length field in UBoot. The U-Boot DFU implementation d...
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
Scope: local
bookworm: resolved (fixed in 2023.01~rc4+dfsg-2)
bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u1)
forky: resolved (fixed in 2023.01~rc4+dfsg-2)
sid: resolved (fixed in 2023.01~rc4+dfsg-2)
trixie: resolved (fixed in 2023.01~rc4+dfsg-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-23
Published