Loading HuntDB...

GHSA-v3qm-xpj7-89x6

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.

Related CVEs

Key Information

GHSA ID
GHSA-v3qm-xpj7-89x6
Published
November 2, 2022 7:00 PM
Last Modified
November 3, 2022 7:00 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.