// For flags

CVE-2022-33967

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.

Una implementación del sistema de archivos squashfs de las versiones de U-Boot versiones desde la v2020.10-rc2 hasta v2022.07-rc5, contiene una vulnerabilidad de desbordamiento de búfer en la región heap de la memoria debido a un defecto en el proceso de lectura de metadatos. La carga de una imagen squashfs especialmente diseñada puede conllevar a una condición de Denegación de Servicio (DoS) o una ejecución de código arbitrario

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-06-29 CVE Reserved
  • 2022-07-20 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-10-11 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2020.10
Search vendor "Denx" for product "U-boot" and version "2020.10"
rc2
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2020.10
Search vendor "Denx" for product "U-boot" and version "2020.10"
rc3
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2020.10
Search vendor "Denx" for product "U-boot" and version "2020.10"
rc4
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2020.10
Search vendor "Denx" for product "U-boot" and version "2020.10"
rc5
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.01
Search vendor "Denx" for product "U-boot" and version "2021.01"
-
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.01
Search vendor "Denx" for product "U-boot" and version "2021.01"
rc1
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.01
Search vendor "Denx" for product "U-boot" and version "2021.01"
rc2
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.01
Search vendor "Denx" for product "U-boot" and version "2021.01"
rc3
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.01
Search vendor "Denx" for product "U-boot" and version "2021.01"
rc4
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.01
Search vendor "Denx" for product "U-boot" and version "2021.01"
rc5
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.04
Search vendor "Denx" for product "U-boot" and version "2021.04"
rc1
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2021.04
Search vendor "Denx" for product "U-boot" and version "2021.04"
rc2
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.01
Search vendor "Denx" for product "U-boot" and version "2022.01"
-
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.01
Search vendor "Denx" for product "U-boot" and version "2022.01"
rc1
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.01
Search vendor "Denx" for product "U-boot" and version "2022.01"
rc2
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.01
Search vendor "Denx" for product "U-boot" and version "2022.01"
rc3
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.01
Search vendor "Denx" for product "U-boot" and version "2022.01"
rc4
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.04
Search vendor "Denx" for product "U-boot" and version "2022.04"
-
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.04
Search vendor "Denx" for product "U-boot" and version "2022.04"
rc1
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.04
Search vendor "Denx" for product "U-boot" and version "2022.04"
rc2
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.04
Search vendor "Denx" for product "U-boot" and version "2022.04"
rc3
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.04
Search vendor "Denx" for product "U-boot" and version "2022.04"
rc4
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.04
Search vendor "Denx" for product "U-boot" and version "2022.04"
rc5
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.07
Search vendor "Denx" for product "U-boot" and version "2022.07"
rc1
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.07
Search vendor "Denx" for product "U-boot" and version "2022.07"
rc2
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.07
Search vendor "Denx" for product "U-boot" and version "2022.07"
rc3
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.07
Search vendor "Denx" for product "U-boot" and version "2022.07"
rc4
Affected
Denx
Search vendor "Denx"
U-boot
Search vendor "Denx" for product "U-boot"
2022.07
Search vendor "Denx" for product "U-boot" and version "2022.07"
rc5
Affected