CVE-2022-30767
16.05.2022, 03:15
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| denx | u-boot | 𝑥 ≤ 2022.04 |
| denx | u-boot | 2022.07:rc1 |
| denx | u-boot | 2022.07:rc2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| u-boot-rpi3 |
| ||||||||||||||||||||||||||||||||||
| u-boot-rpiarm64 |
| ||||||||||||||||||||||||||||||||||
| u-boot-rpiarm64-doc |
| ||||||||||||||||||||||||||||||||||
| u-boot-tools |
|
References