7.8
CVSSv3

CVE-2022-30790

Published: 08/06/2022 Updated: 16/06/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

It exists that U-Boot incorrectly handled certain NFS lookup replies. A remote attacker could use this issue to cause U-Boot to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30767)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

denx u-boot 2022.01

Vendor Advisories

Debian Bug report logs - #1014470 u-boot: CVE-2022-30552 CVE-2022-30790 Package: src:u-boot; Maintainer for src:u-boot is Vagrant Cascadian <vagrant@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 6 Jul 2022 15:27:02 UTC Severity: important Tags: security, upstream Reply or subscribe t ...
Several security issues were fixed in u-boot ...