← Back

CVE-2022-33967

nvd nist
Published: Jul 20, 2022Modified: Nov 3, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.

Affected (28)

Products: Denx: U Boot
1 product
U Boot
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Denx
Version 2020.10 rc2
Version 2020.10 rc3
Version 2020.10 rc4
Version 2020.10 rc5
Version 2021.01
Version 2021.01 rc1
Version 2021.01 rc2
Version 2021.01 rc3
Version 2021.01 rc4
Version 2021.01 rc5
Version 2021.04 rc1
Version 2021.04 rc2
Version 2022.01
Version 2022.01 rc1
Version 2022.01 rc2
Version 2022.01 rc3
Version 2022.01 rc4
Version 2022.04
Version 2022.04 rc1
Version 2022.04 rc2
Version 2022.04 rc3
Version 2022.04 rc4
Version 2022.04 rc5
Version 2022.07 rc1
Version 2022.07 rc2
Version 2022.07 rc3
Version 2022.07 rc4
Version 2022.07 rc5

References (9)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
ExploitMailing ListVendor Advisory
Source: vultures@jpcert.or.jp
PatchThird Party AdvisoryVendor Advisory
Source: vultures@jpcert.or.jp
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.