First published: Fri Jul 01 2022(Updated: )
Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DENX U-Boot | >=2020.10<2022.07 | |
DENX U-Boot | =2022.07-rc1 | |
DENX U-Boot | =2022.07-rc2 | |
DENX U-Boot | =2022.07-rc3 | |
ubuntu/u-boot | <2020.10+dfsg-1ubuntu0~18.04.3 | 2020.10+dfsg-1ubuntu0~18.04.3 |
ubuntu/u-boot | <2021.01+dfsg-3ubuntu0~20.04.5 | 2021.01+dfsg-3ubuntu0~20.04.5 |
ubuntu/u-boot | <2022.01+dfsg-2ubuntu2.3 | 2022.01+dfsg-2ubuntu2.3 |
debian/u-boot | <=2021.01+dfsg-5 | 2019.01+dfsg-7 2023.01+dfsg-2 2024.01+dfsg-1 2024.01+dfsg-5 |
https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw@mail.gmail.com/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33103 is a vulnerability in Das U-Boot versions from v2020.10 to v2022.07-rc3 that allows an out-of-bounds write via the sqfs_readdir() function.
The severity of CVE-2022-33103 is high, with a CVSS score of 7.8.
Das U-Boot versions from v2020.10 to v2022.07-rc3, as well as version 2022.07-rc1, 2022.07-rc2, and 2022.07-rc3, are affected by CVE-2022-33103.
To fix CVE-2022-33103, it is recommended to update Das U-Boot to a version beyond v2022.07-rc3.
More information about CVE-2022-33103 can be found at the following references: [Link 1](https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal@bootlin.com/) and [Link 2](https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw@mail.gmail.com/).