How to verify that the CVE-2023-39902 issue has been fixed?

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

How to verify that the CVE-2023-39902 issue has been fixed?

ソリューションへジャンプ
760件の閲覧回数
ZongYue
Contributor I

By using NXP U-Boot version lf-5.15.5-1.0.0 on the i.MX8MP platform and referencing the patch for CVE-2023-39902 (U-Boot Secondary Program Loader Authentication Vulnerability - CVE-2023-39902 ) from NXP version lf-6.12.3-1.0.0.

This modification appears to address two issues:

  1. Stack overflow caused by excessively long bootargs

  2. U-Boot Secondary Program Loader (SPL) authentication vulnerability

How can we verify that these issues have been successfully fixed in the modified lf-5.15.5-1.0.0 U-Boot?

 

ラベル(1)
0 件の賞賛
返信
1 解決策
710件の閲覧回数
Harvey021
NXP TechSupport
NXP TechSupport

Will send you system email with bootport patchs for the version of BSP.

 

Regards

Harvey

元の投稿で解決策を見る

0 件の賞賛
返信
2 返答(返信)
704件の閲覧回数
ZongYue
Contributor I

Hi @Harvey021 ,

Thank you for providing the patch file for version lf-5.15.5-1.0.0.

0 件の賞賛
返信
711件の閲覧回数
Harvey021
NXP TechSupport
NXP TechSupport

Will send you system email with bootport patchs for the version of BSP.

 

Regards

Harvey

0 件の賞賛
返信