nfslookupreply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "net/nfs.c" }, "id": "CVE-2022-30767-357a11fe", "digest": { "line_hashes": [ "26433567509784795861491119420591390178", "139851264388448427586386885273476681982", "102566397628219876016957460735237255863", "10464583766473143428314599776778313463", "250100618551608620223203281115845299151", "220106819974186756061365701647976297066", "291421002495152642350750009756020206005", "73407787953136352830763228951237775210", "178207664579366023471673552940890338857" ], "threshold": 0.9 }, "deprecated": false, "source": "https://github.com/u-boot/u-boot/commit/5d14ee4e53a81055d34ba280cb8fd90330f22a96" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "net/nfs.c", "function": "nfs_lookup_reply" }, "id": "CVE-2022-30767-9cd6cc4d", "digest": { "length": 1847.0, "function_hash": "301104250594287063405529259447799514173" }, "deprecated": false, "source": "https://github.com/u-boot/u-boot/commit/5d14ee4e53a81055d34ba280cb8fd90330f22a96" } ] }