CVE-2022-30767

CRITICAL

Das U-Boot <2022.04 - Buffer Overflow

Title source: llm
STIX 2.1

Description

nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.

Scores

CVSS v3 9.8
EPSS 0.0015
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (3)
denx/u-boot 2022.07 rc1 (2 CPE variants)
denx/u-boot < 2022.04
fedoraproject/fedora 36
Published May 16, 2022
Tracked Since Feb 18, 2026