Executive brief
Das U-Boot is a widely used open-source bootloader for embedded devices, such as routers, industrial controllers, and IoT hardware. A security flaw has been identified that could allow a local attacker to cause a system crash or potentially execute unauthorized code. This could lead to a complete loss of device availability or unauthorized access to sensitive data stored on the hardware.
Technical details
A buffer overflow vulnerability exists in Das U-Boot version 2022.01 due to an out-of-bounds write (CWE-787). The flaw is distinct from CVE-2022-30552. An attacker with local access and low privileges can exploit this vulnerability to overwrite memory, potentially achieving arbitrary code execution or causing a system crash (denial-of-service). The vulnerability has been observed in downstream implementations, such as Siemens RUGGEDCOM ROX II devices. Patches are available in newer versions of U-Boot and vendor-specific firmware updates like RUGGEDCOM ROX V2.17.1.
Affected products
- Das U-Boot U-Boot 2022.01
- Siemens Corproation RUGGEDCOM ROX II family All versions < V2.17.1
Timeline
- 2022-06-03: disclosed: Technical advisory published by NCC Group
- 2022-06-08: advisory: NVD published CVE-2022-30790
- 2025-05-01: patched: Debian LTS security update released
- 2026-05-12: patched: Siemens released advisory SSA-577017 with fixes for RUGGEDCOM ROX II