SUSE-SU-2022:2052-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2052-1
SUSE-SU-2022:2052-1
Summary: Security update for u-boot
Details: This update for u-boot fixes the following issues: - CVE-2022-30552: A large buffer overflow could have lead to a denial of service in the IP Packet deframentation code. (bsc#1200363) - CVE-2022-30790: A Hole Descriptor Overwrite could have lead to an arbitrary out of bounds write primitive. (bsc#1200364) - CVE-2022-30767: Fixed an unbounded memcpy with a failed length check leading to a buffer overflow (bsc#1199623).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222052-1/, https://bugzilla.suse.com/1199623, https://bugzilla.suse.com/1200363, https://bugzilla.suse.com/1200364, https://www.suse.com/security/cve/CVE-2022-30552, https://www.suse.com/security/cve/CVE-2022-30767, https://www.suse.com/security/cve/CVE-2022-30790
Affected packages
Package
Name: u-boot
Purl: pkg:rpm/suse/u-boot&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
