CVE-2022-2347
7.1
HIGH
CVSS 3.1
EPSS 0.04%
Description
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
How to fix CVE-2022-2347
To remediate CVE-2022-2347, upgrade the affected package to a fixed version below.
- —upgrade to 2021.01+dfsg-5+deb11u1 or later
Is CVE-2022-2347 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2021.01+dfsg-5+deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |