High severity7.8NVD Advisory· Published Jul 20, 2022· Updated Jun 17, 2026
CVE-2022-33967
CVE-2022-33967
Description
squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
89- osv-coords87 versionspkg:rpm/opensuse/u-boot-avnetultra96rev1&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-avnetultra96rev1&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-bananapim64&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-bananapim64&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-dragonboard410c&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-dragonboard410c&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-dragonboard820c&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-dragonboard820c&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-evb-rk3399&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-evb-rk3399&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-firefly-rk3399&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-firefly-rk3399&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-geekbox&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-geekbox&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-hikey&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-hikey&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-khadas-vim2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-khadas-vim2&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-khadas-vim&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-khadas-vim&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-libretech-ac&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-libretech-ac&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-libretech-cc&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-libretech-cc&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-ls1012afrdmqspi&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-ls1012afrdmqspi&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-mvebudb-88f3720&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-mvebudb-88f3720&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-mvebudbarmada8k&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-mvebudbarmada8k&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-mvebuespressobin-88f3720&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-mvebuespressobin-88f3720&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-mvebumcbin-88f8040&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-mvebumcbin-88f8040&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-nanopia64&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-nanopia64&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-odroid-c2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-odroid-c2&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-odroid-c4&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-odroid-c4&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-odroid-n2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-odroid-n2&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-orangepipc2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-orangepipc2&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-p2371-2180&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-p2371-2180&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-p2771-0000-500&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-p2771-0000-500&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-p3450-0000&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-p3450-0000&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-pine64plus&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-pine64plus&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-pinebook&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-pinebook&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-pinebook-pro-rk3399&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-pinebook-pro-rk3399&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-pineh64&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-pineh64&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-pinephone&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-pinephone&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-poplar&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-poplar&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rock64-rk3328&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rock64-rk3328&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rock960-rk3399&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rock960-rk3399&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rock-pi-4-rk3399&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rock-pi-4-rk3399&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rock-pi-n10-rk3399pro&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rockpro64-rk3399&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rockpro64-rk3399&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rpi3&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rpi3&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rpi4&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rpi4&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-rpiarm64&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-rpiarm64&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-xilinxzynqmpvirt&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-xilinxzynqmpvirt&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/u-boot-xilinxzynqmpzcu102rev10&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/u-boot-xilinxzynqmpzcu102rev10&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/u-boot&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/u-boot&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/u-boot-rpiarm64&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
< 2021.01-150300.7.15.1+ 86 more
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
- (no CPE)range: < 2021.01-150300.7.15.1
- (no CPE)range: < 2021.10-150400.4.8.1
Patches
Vulnerability mechanics
References
5- source.denx.de/u-boot/u-boot/-/commit/7f7fb9937c6cb49dd35153bd6708872b390b0a44nvdPatchThird Party AdvisoryVendor Advisory
- lists.denx.de/pipermail/u-boot/2022-June/487467.htmlnvdExploitMailing ListVendor Advisory
- jvn.jp/en/vu/JVNVU97846460/index.htmlnvdThird Party Advisory
- www.denx.de/project/u-boot/nvdProduct
- lists.debian.org/debian-lts-announce/2025/05/msg00001.htmlnvd
News mentions
0No linked articles in our index yet.