CVE-2022-3055208.06.2022, 13:15Das U-Boot 2022.01 has a Buffer Overflow.Classic Buffer OverflowEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST5.5 MEDIUMLOCALLOWLOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 28%VendorProductVersiondenxu-boot2022.01𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenameu-bootbullseyeno-dsabusterno-dsastretchno-dsabookworm2023.01+dfsg-2+deb12u1fixedsid2024.01+dfsg-5fixedtrixie2024.01+dfsg-5fixedUbuntu ReleasesUbuntu ProductCodenameu-bootnoblenot-affectedmanticnot-affectedlunarnot-affectedkineticnot-affectedjammyFixed 2022.01+dfsg-2ubuntu2.3releasedimpishignoredfocalFixed 2021.01+dfsg-3ubuntu0~20.04.5releasedbionicFixed 2020.10+dfsg-1ubuntu0~18.04.3releasedxenialneeds-triageu-boot-nezhanobleneededmanticignoredlunarFixed 2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2releasedkineticignoredjammyFixed 2022.04+git20220405.7446a472-0ubuntu0.4releasedfocaldnebionicdnexenialignoredtrustyignoredCommon Weakness EnumerationCWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')The program copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.Referenceshttps://github.com/u-boot/u-boot/tagshttps://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/https://github.com/u-boot/u-boot/tagshttps://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/