USN-6523-1: u-boot-nezha vulnerability
It was discovered that U-Boot incorrectly handled certain USB DFU download setup packets. A local attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-2347) Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled certain fragmented IP packets. A local attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-30552, CVE-2022-30790)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2022-2347.
What is the severity of the u-boot-nezha vulnerability?
The severity of the u-boot-nezha vulnerability is not mentioned in the advisory.
How does this vulnerability impact U-Boot?
This vulnerability in U-Boot can cause it to crash, resulting in a denial of service, or possibly execute arbitrary code.
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability by using certain USB DFU download setup packets.
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability in the Ubuntu u-boot-nezha package.