CVE-2022-24936: Gecko Standalone Bootloader vulnerability may allow bypassing application secure boot in some Series 2 devices
Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24936?
CVE-2022-24936 is an out-of-bounds error vulnerability in the GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier.
How does CVE-2022-24936 affect the affected software?
CVE-2022-24936 allows attackers to overwrite the flash Sign key and OTA decryption key through a malicious bootloader upgrade.
What is the severity of CVE-2022-24936?
CVE-2022-24936 has a severity rating of 9.1 (Critical).
How can I fix CVE-2022-24936?
To fix CVE-2022-24936, update to a version of Silicon Labs Gecko Bootloader that is later than 4.0.1.
Where can I find more information about CVE-2022-24936?
More information about CVE-2022-24936 can be found at the following references: [Reference 1](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000Gdop4QAB?operationContext=S1), [Reference 2](https://github.com/SiliconLabs/gecko_sdk/blame/2e82050dc8823c9fe0e8908c1b2666fb83056230/platform/bootloader/core/btl_bootload.c)