USN-6523-1
Dashboard / Vulnerabilities / USN-6523-1
USN-6523-1
Summary: u-boot-nezha vulnerability
Details: It was discovered that U-Boot incorrectly handled certain USB DFU download setup packets. A local attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-2347) Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled certain fragmented IP packets. A local attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-30552, CVE-2022-30790)
References: https://ubuntu.com/security/notices/USN-6523-1, https://ubuntu.com/security/CVE-2022-2347, https://ubuntu.com/security/CVE-2022-30552, https://ubuntu.com/security/CVE-2022-30790
Affected packages
Package
Name: u-boot-nezha
Purl: pkg:deb/ubuntu/[email protected]+git20220405.7446a472-0ubuntu0.4?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
