VYPR
Critical severity9.8NVD Advisory· Published Jun 30, 2022· Updated May 12, 2026

CVE-2022-34835

CVE-2022-34835

Description

In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.

Affected products

7
  • Das/U-Bootdescription
  • Denx/U Boot6 versions
    cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*range: <2022.07
    • cpe:2.3:a:denx:u-boot:2022.07:rc1:*:*:*:*:*:*
    • cpe:2.3:a:denx:u-boot:2022.07:rc2:*:*:*:*:*:*
    • cpe:2.3:a:denx:u-boot:2022.07:rc3:*:*:*:*:*:*
    • cpe:2.3:a:denx:u-boot:2022.07:rc4:*:*:*:*:*:*
    • cpe:2.3:a:denx:u-boot:2022.07:rc5:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

1