CVE-2022-34835 is a critical stack-based buffer overflow vulnerability in Das U-Boot through version 2022.07-rc5, specifically within the "i2c md" command. This flaw, rated 9.8 CVSS, allows an unauthenticated attacker to remotely corrupt the return address pointer of the do_i2c_md function, leading to full compromise (confidentiality, integrity, and availability). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | ||
2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.07:rc1:*:*:*:*:*:* | ||
2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.07:rc2:*:*:*:*:*:* | ||
2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.07:rc3:*:*:*:*:*:* | ||
2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.07:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.