7.8

CVE-2022-33967

Exploit

squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
DenxU-boot Version2020.10 Updaterc2
DenxU-boot Version2020.10 Updaterc3
DenxU-boot Version2020.10 Updaterc4
DenxU-boot Version2020.10 Updaterc5
DenxU-boot Version2021.01 Update-
DenxU-boot Version2021.01 Updaterc1
DenxU-boot Version2021.01 Updaterc2
DenxU-boot Version2021.01 Updaterc3
DenxU-boot Version2021.01 Updaterc4
DenxU-boot Version2021.01 Updaterc5
DenxU-boot Version2021.04 Updaterc1
DenxU-boot Version2021.04 Updaterc2
DenxU-boot Version2022.01 Update-
DenxU-boot Version2022.01 Updaterc1
DenxU-boot Version2022.01 Updaterc2
DenxU-boot Version2022.01 Updaterc3
DenxU-boot Version2022.01 Updaterc4
DenxU-boot Version2022.04 Update-
DenxU-boot Version2022.04 Updaterc1
DenxU-boot Version2022.04 Updaterc2
DenxU-boot Version2022.04 Updaterc3
DenxU-boot Version2022.04 Updaterc4
DenxU-boot Version2022.04 Updaterc5
DenxU-boot Version2022.07 Updaterc1
DenxU-boot Version2022.07 Updaterc2
DenxU-boot Version2022.07 Updaterc3
DenxU-boot Version2022.07 Updaterc4
DenxU-boot Version2022.07 Updaterc5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.5% 0.649
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.