Executive brief
A buffer overflow vulnerability exists in U-Boot, a widely used bootloader for embedded systems and industrial hardware. An attacker with local access to the system could exploit this flaw to cause a system crash or denial-of-service, potentially disrupting critical operations or industrial processes. This issue affects various embedded devices, including Siemens Ruggedcom networking equipment.
Technical details
A classic buffer overflow (CWE-120) exists in Das U-Boot version 2022.01. The vulnerability stems from a buffer copy operation that does not properly check the size of the input. An attacker with local access and low privileges can exploit this to trigger a crash, resulting in a denial-of-service (DoS) by impacting the availability of the bootloader. While the primary impact is availability, buffer overflows in bootloaders can sometimes be leveraged for more complex exploitation depending on the specific implementation. Patches have been made available in downstream distributions like Debian (version 2021.01+dfsg-5+deb11u1) and integrated into vendor firmware such as Siemens Ruggedcom ROX (V2.17.1).
Affected products
- Das U-Boot U-Boot 2022.01
- Siemens Ruggedcom Rox II family < V2.17.1
Timeline
- 2022-06-03: advisory: Technical advisory published by NCC Group
- 2022-06-08: disclosed: CVE published in NVD
- 2025-05-01: patched: Debian LTS security update released
- 2026-05-12: advisory: Siemens SSA-577017 advisory published