VulnerabilityModified
CVE-2022-30767
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow.
CRITICAL 9.8EPSS 2.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- denx/u-boot · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://github.com/u-boot/u-boot/commit/5d14ee4e53a81055d34ba280cb8fd90330f22a96Patch, Third Party Advisory
- https://lists.denx.de/pipermail/u-boot/2022-May/483952.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
- https://securitylab.github.com/research/uboot-rce-nfs-vulnerability/Exploit, Third Party Advisory
- https://source.denx.de/u-boot/u-boot/-/commit/bdbf7a05e26f3c5fd437c99e2755ffde186ddc80Patch, Vendor Advisory
- https://github.com/u-boot/u-boot/commit/5d14ee4e53a81055d34ba280cb8fd90330f22a96Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/05/msg00001.html
- https://lists.denx.de/pipermail/u-boot/2022-May/483952.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
- https://securitylab.github.com/research/uboot-rce-nfs-vulnerability/Exploit, Third Party Advisory
- https://source.denx.de/u-boot/u-boot/-/commit/bdbf7a05e26f3c5fd437c99e2755ffde186ddc80Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.