CVE Database
/

CVE-2022-33967

Back to search

CVE-2022-33967

Published: Jul 20, 2022

Modified: Nov 3, 2025

PUBLISHED

Description

squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.

VendorProductVersions

DENX Software Engineering

U-Boot

affected
versions from v2020.10-rc2 to v2022.07-rc5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now