Vulnerability Name:

CVE-2022-33967 (CCN-230980)

Assigned:2022-07-12
Published:2022-07-12
Updated:2022-08-02
Summary:squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Physical
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2022-33967

Source: CCN
Type: JVNVU#97846460
U-Boot squashfs filesystem implementation vulnerable to heap-based buffer overflow

Source: XF
Type: UNKNOWN
uboot-cve202233967-bo(230980)

Source: MISC
Type: Third Party Advisory
https://jvn.jp/en/vu/JVNVU97846460/index.html

Source: MISC
Type: Exploit, Mailing List, Vendor Advisory
https://lists.denx.de/pipermail/u-boot/2022-June/487467.html

Source: MISC
Type: Patch, Third Party Advisory, Vendor Advisory
https://source.denx.de/u-boot/u-boot/-/commit/7f7fb9937c6cb49dd35153bd6708872b390b0a44

Source: CCN
Type: DENX Web site
U-Boot

Source: MISC
Type: Product
https://www.denx.de/project/u-boot/

Vulnerable Configuration:Configuration 1:
  • cpe:/a:denx:u-boot:2021.04:rc1:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.07:rc2:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.07:rc1:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.01:-:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.07:rc3:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.07:rc4:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.07:rc5:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2020.10:rc2:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2020.10:rc3:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.01:-:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.01:rc1:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.01:rc2:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.01:rc3:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.01:rc4:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.01:rc5:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2021.04:rc2:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.01:rc1:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.01:rc2:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.01:rc3:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.01:rc4:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.04:-:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.04:rc1:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.04:rc2:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.04:rc3:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.04:rc4:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2022.04:rc5:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2020.10:rc4:*:*:*:*:*:*
  • OR cpe:/a:denx:u-boot:2020.10:rc5:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7820
    P
    u-boot-rpiarm64-2021.10-150400.4.11.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3664
    P
    Security update for u-boot (Important)
    2022-08-03
    oval:org.opensuse.security:def:95294
    P
    Security update for u-boot (Important)
    2022-08-03
    oval:org.opensuse.security:def:673
    P
    Security update for u-boot (Important)
    2022-08-03
    BACK
    denx u-boot 2021.04 rc1
    denx u-boot 2022.07 rc2
    denx u-boot 2022.07 rc1
    denx u-boot 2022.01 -
    denx u-boot 2022.07 rc3
    denx u-boot 2022.07 rc4
    denx u-boot 2022.07 rc5
    denx u-boot 2020.10 rc2
    denx u-boot 2020.10 rc3
    denx u-boot 2021.01 -
    denx u-boot 2021.01 rc1
    denx u-boot 2021.01 rc2
    denx u-boot 2021.01 rc3
    denx u-boot 2021.01 rc4
    denx u-boot 2021.01 rc5
    denx u-boot 2021.04 rc2
    denx u-boot 2022.01 rc1
    denx u-boot 2022.01 rc2
    denx u-boot 2022.01 rc3
    denx u-boot 2022.01 rc4
    denx u-boot 2022.04 -
    denx u-boot 2022.04 rc1
    denx u-boot 2022.04 rc2
    denx u-boot 2022.04 rc3
    denx u-boot 2022.04 rc4
    denx u-boot 2022.04 rc5
    denx u-boot 2020.10 rc4
    denx u-boot 2020.10 rc5