Vulnerability Description
Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
CVSS Score
7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Denx | U-Boot | >= 2020.10, < 2022.07 |
Related Weaknesses (CWE)
References
- https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal%40bootlin.com/
- https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw%
- https://lists.debian.org/debian-lts-announce/2025/05/msg00001.html
- https://lore.kernel.org/all/20220609140206.297405-1-miquel.raynal%40bootlin.com/
- https://lore.kernel.org/all/CALO=DHFB+yBoXxVr5KcsK0iFdg+e7ywko4-e+72kjbcS8JBfPw%
FAQ
What is CVE-2022-33103?
CVE-2022-33103 is a vulnerability with a CVSS score of 7.8 (HIGH). Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().
How severe is CVE-2022-33103?
CVE-2022-33103 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-33103?
Check the references section above for vendor advisories and patch information. Affected products include: Denx U-Boot.