squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2022-07-20T06:15:22

Updated: 2024-08-03T08:16:16.135Z

Reserved: 2022-06-29T00:00:00

Link: CVE-2022-33967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-20T07:15:08.667

Modified: 2022-08-02T16:44:14.300

Link: CVE-2022-33967

cve-icon Redhat

No data.