All errata/sisyphus/ALT-PU-2022-2727-2
ALT-PU-2022-2727-2

Package update u-boot-tools in branch sisyphus

Version2022.10-alt1
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (2)

BDU:2025-13599
HIGH7.7

Уязвимость компонента drivers/usb/gadget/f_dfu.c загрузчика U-Boot, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

Published: 2025-10-31
CVSS 3.xHIGH 7.7
CVSS:3.x/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.2
CVSS:2.0/AV:L/AC:H/Au:N/C:C/I:C/A:C
References
CVE-2022-2347
HIGH7.1

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

Published: 2022-09-23Modified: 2025-11-03
CVSS 3.xHIGH 7.1
CVSS:3.x/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H