How to verify that the CVE-2023-39902 issue has been fixed?

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 
已解决

How to verify that the CVE-2023-39902 issue has been fixed?

跳至解决方案
522 次查看
ZongYue
Contributor I

By using NXP U-Boot version lf-5.15.5-1.0.0 on the i.MX8MP platform and referencing the patch for CVE-2023-39902 (U-Boot Secondary Program Loader Authentication Vulnerability - CVE-2023-39902 ) from NXP version lf-6.12.3-1.0.0.

This modification appears to address two issues:

  1. Stack overflow caused by excessively long bootargs

  2. U-Boot Secondary Program Loader (SPL) authentication vulnerability

How can we verify that these issues have been successfully fixed in the modified lf-5.15.5-1.0.0 U-Boot?

 

标签 (1)
0 项奖励
回复
1 解答
472 次查看
Harvey021
NXP TechSupport
NXP TechSupport

Will send you system email with bootport patchs for the version of BSP.

 

Regards

Harvey

在原帖中查看解决方案

0 项奖励
回复
2 回复数
466 次查看
ZongYue
Contributor I

Hi @Harvey021 ,

Thank you for providing the patch file for version lf-5.15.5-1.0.0.

0 项奖励
回复
473 次查看
Harvey021
NXP TechSupport
NXP TechSupport

Will send you system email with bootport patchs for the version of BSP.

 

Regards

Harvey

0 项奖励
回复