Описание
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 2020.10+dfsg-1ubuntu0~18.04.3 |
devel | not-affected | 2022.07+dfsg-1ubuntu4 |
esm-infra/bionic | not-affected | 2020.10+dfsg-1ubuntu0~18.04.3 |
esm-infra/focal | not-affected | 2021.01+dfsg-3ubuntu0~20.04.5 |
esm-infra/xenial | needed | |
focal | released | 2021.01+dfsg-3ubuntu0~20.04.5 |
impish | ignored | end of life |
jammy | released | 2022.01+dfsg-2ubuntu2.3 |
kinetic | not-affected | 2022.07+dfsg-1ubuntu4 |
lunar | not-affected | 2022.07+dfsg-1ubuntu4 |
Показывать по
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and throu ...
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
Уязвимость функции nfs_lookup_reply (net/nfs.c) загрузчика U-Boot встроенных операционных систем на базе Linux, позволяющая нарушителю выполнить произвольный код
7.5 High
CVSS2
9.8 Critical
CVSS3