Privilege Escalation Vulnerability in U-Boot SPL for NXP i.MX 8M Processors
CVE-2023-39902

7HIGH

Key Information:

Vendor

Nxp

Vendor
CVE Published:
17 October 2023

What is CVE-2023-39902?

A software vulnerability has been discovered in the U-Boot Secondary Program Loader (SPL) prior to version 2023.07 that affects select NXP i.MX 8M family processors. This vulnerability arises from a flaw that allows a specially crafted Flattened Image Tree (FIT) format structure to overwrite memory within the SPL. Under specific conditions, this can result in the execution of unauthenticated software, facilitating privilege escalation on affected devices. Key processors impacted include i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus, making it essential for users to review their security configurations and apply necessary updates.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.