CVE-2022-34835: exploitation status and patch state
CVE-2022-34835 · CVSS 9.8 CRITICAL · EPSS 2%
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
Is CVE-2022-34835 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 2%.
Public exploit code: none found in monitored sources.