Out-of-Bounds Write Vulnerability in Das U-Boot by Bootlin
CVE-2022-33103

7.8HIGH

Key Information:

Vendor

Denx

Status
Vendor
CVE Published:
1 July 2022

What is CVE-2022-33103?

The recent vulnerability in Das U-Boot affects multiple versions and is characterized by an out-of-bounds write occurring in the function sqfs_readdir(). This flaw may allow attackers to exploit memory manipulation, potentially leading to unauthorized access or system instability. Users are advised to review the affected versions and apply necessary updates to safeguard their systems against potential threats.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.