Logo
vulnerabilityCVE-2022-33967
Name
CVE-2022-33967
Source
NVD ( link)Debian ( link)
Description
squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
u-boot
Exploitable

Vulnerability Rating#


7.8
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2021.07
Not Affected
buildroot
master
2026.04
Not Affected
yocto
master
2026.04
Not Affected
yocto
scarthgap
2024.01
Not Affected