UBUNTU-CVE-2022-33967
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-33967
UBUNTU-CVE-2022-33967
Summary:
Details: squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
References: https://ubuntu.com/security/CVE-2022-33967, https://www.denx.de/project/u-boot/, https://lists.denx.de/pipermail/u-boot/2022-June/487467.html, https://jvn.jp/en/vu/JVNVU97846460/index.html, https://ubuntu.com/security/notices/USN-5764-1, https://www.cve.org/CVERecord?id=CVE-2022-33967
Affected packages
Package
Name: u-boot
Purl: pkg:deb/ubuntu/[email protected]+dfsg1-2ubuntu5?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
