https://seclists.org/oss-sec/2022/q3/41
Published Jul 8, 2022
·Updated
Affected Software
1 affected component
DENX Software Engineering U-Boot>=v2012.10-rc1<<version of fix
Frequently Asked Questions
1
What is the severity of CVE-2022-2347?
CVE-2022-2347 has been assigned a medium severity rating due to potential arbitrary code execution risks.
2
How do I fix CVE-2022-2347?
To mitigate CVE-2022-2347, update U-Boot to the latest version where the vulnerability has been addressed.
3
What systems are affected by CVE-2022-2347?
CVE-2022-2347 affects systems that utilize the U-Boot bootloader in their firmware.
4
What does CVE-2022-2347 exploit?
CVE-2022-2347 exploits unchecked download size and direction in the USB Device Firmware Upgrade (DFU) functionality.
5
What are the potential impacts of CVE-2022-2347?
The potential impacts of CVE-2022-2347 include arbitrary code execution, which can compromise the integrity of affected devices.