CVE-2022-34835
Summary
| CVE | CVE-2022-34835 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-30 00:15:00 UTC |
| Updated | 2023-08-29 17:55:00 UTC |
| Description | In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Denx |
U-boot |
All |
All |
All |
All |
| Application |
Denx |
U-boot |
2022.07 |
rc1 |
All |
All |
| Application |
Denx |
U-boot |
2022.07 |
rc2 |
All |
All |
| Application |
Denx |
U-boot |
2022.07 |
rc3 |
All |
All |
| Application |
Denx |
U-boot |
2022.07 |
rc4 |
All |
All |
| Application |
Denx |
U-boot |
2022.07 |
rc5 |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [PATCH] i2c: fix stack buffer overflow vulnerability in i2c md command |
MISC |
lists.denx.de |
|
| i2c: fix stack buffer overflow vulnerability in i2c md command · u-boot/u-boot@8f8c04b · GitHub |
MISC |
github.com |
|
| i2c: fix stack buffer overflow vulnerability in i2c md command (8f8c04bf) · Commits · U-Boot / U-Boot · GitLab |
MISC |
source.denx.de |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182821 Debian Security Update for u-boot (CVE-2022-34835)
- 199065 Ubuntu Security Notification for U-Boot Vulnerabilities (USN-5764-1)
- 672088 EulerOS Security Update for uboot-tools (EulerOS-SA-2022-2335)
- 672089 EulerOS Security Update for uboot-tools (EulerOS-SA-2022-2306)
- 672173 EulerOS Security Update for uboot-tools (EulerOS-SA-2022-2422)
- 672177 EulerOS Security Update for uboot-tools (EulerOS-SA-2022-2435)
- 752407 SUSE Enterprise Linux Security Update for u-boot (SUSE-SU-2022:2584-1)
- 752420 SUSE Enterprise Linux Security Update for u-boot (SUSE-SU-2022:2654-1)
- 752434 SUSE Enterprise Linux Security Update for u-boot (SUSE-SU-2022:2661-1)
- 752437 SUSE Enterprise Linux Security Update for u-boot (SUSE-SU-2022:2653-1)
- 752441 SUSE Enterprise Linux Security Update for u-boot (SUSE-SU-2022:2666-1)
- 752445 SUSE Enterprise Linux Security Update for u-boot (SUSE-SU-2022:2667-1)