Lucene search

K
cvelistJpcertCVELIST:CVE-2022-33967
HistoryJul 20, 2022 - 6:15 a.m.

CVE-2022-33967

2022-07-2006:15:22
jpcert
www.cve.org

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.2%

squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.

CNA Affected

[
  {
    "product": "U-Boot",
    "vendor": "DENX Software Engineering",
    "versions": [
      {
        "status": "affected",
        "version": "versions from v2020.10-rc2 to v2022.07-rc5"
      }
    ]
  }
]

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.2%