cvedb.io
CVE-2022-34835
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2022-06-30T00:15:08.023 · Last modified 2026-06-17T04:51:01.070

Summary

In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.

Affected products

denx — u-boot

Does this affect you?

Add your gear to cvedb and we'll alert you only when denx ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.