VYPR
Unrated severityNVD Advisory· Published Oct 17, 2023· Updated Sep 16, 2024

CVE-2023-39902

CVE-2023-39902

Description

A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • NXP/U-Boot Secondary Program Loaderdescription
  • Nxp/U-Boot SPLllm-create
    Range: <2023.07

Patches

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.