CVE-2022-30767 is a critical buffer overflow vulnerability in the nfs_lookup_reply function within Das U-Boot through version 2022.04 (and 2022.07-rc2), affecting products like Denx U-Boot and Fedora. This flaw, stemming from an incorrect fix for CVE-2019-14196, allows for unauthenticated remote code execution due to an unbounded memcpy operation. With a CVSS score of 9.8, it presents a severe risk of complete compromise (confidentiality, integrity, availability) with low attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not widely targeted at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022.04CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | ||
2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.07:rc1:*:*:*:*:*:* | ||
2022.07CPE matchmatch criteria | cpe:2.3:a:denx:u-boot:2022.07:rc2:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.