nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
2022-05-16T03:15:07.563
2024-11-21T07:03:20.180
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | denx | u-boot | ≤ 2022.04 | Yes |
Application | denx | u-boot | 2022.07 | Yes |
Application | denx | u-boot | 2022.07 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |