CVE-2022-33103

Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2022.07:rc1:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2022.07:rc2:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2022.07:rc3:*:*:*:*:*:*

History

07 Nov 2023, 03:48

Type Values Removed Values Added
References
  • {'url': 'https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal@bootlin.com/', 'name': 'https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal@bootlin.com/', 'tags': ['Exploit', 'Mailing List', 'Patch', 'Third Party Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw@mail.gmail.com/', 'name': 'https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw@mail.gmail.com/', 'tags': ['Exploit', 'Mailing List', 'Patch', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal%40bootlin.com/ -
  • () https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw%40mail.gmail.com/ -

15 Jul 2022, 16:50

Type Values Removed Values Added
First Time Denx
Denx u-boot
CPE cpe:2.3:a:denx:u-boot:2022.07:rc1:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2022.07:rc2:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:2022.07:rc3:*:*:*:*:*:*
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
References (MISC) https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal@bootlin.com/ - (MISC) https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal@bootlin.com/ - Exploit, Mailing List, Patch, Third Party Advisory
References (MISC) https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw@mail.gmail.com/ - (MISC) https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw@mail.gmail.com/ - Exploit, Mailing List, Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CWE CWE-787

01 Jul 2022, 12:53

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-01 12:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-33103

Mitre link : CVE-2022-33103

CVE.ORG link : CVE-2022-33103


JSON object : View

Products Affected

denx

  • u-boot
CWE
CWE-787

Out-of-bounds Write