CVE-2022-30790
published 2022-06-08CVE-2022-30790: Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.55%
42.9th percentile
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | u-boot | < u-boot 2022.07+dfsg-1 (bookworm) | u-boot 2022.07+dfsg-1 (bookworm) |
| denx | u-boot | — | — |
| denx | u-boot | >= 0 < 2021.01+dfsg-5+deb11u1 | 2021.01+dfsg-5+deb11u1 |
| denx | u-boot | >= 0 < 2022.07+dfsg-1 | 2022.07+dfsg-1 |
| denx | u-boot | >= 0 < 2022.07+dfsg-1 | 2022.07+dfsg-1 |
| denx | u-boot | >= 0 < 2022.07+dfsg-1 | 2022.07+dfsg-1 |
| denx | u-boot | >= 0 < 2020.10+dfsg-1ubuntu0~18.04.3 | 2020.10+dfsg-1ubuntu0~18.04.3 |
| denx | u-boot | >= 0 < 2021.01+dfsg-3ubuntu0~20.04.5 | 2021.01+dfsg-3ubuntu0~20.04.5 |
| denx | u-boot | >= 0 < 2022.01+dfsg-2ubuntu2.3 | 2022.01+dfsg-2ubuntu2.3 |
| msrc | azl3_qemu_8.2.0-16_on_azure_linux_3.0 | — | — |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.1HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.7HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
u-boot-nezha vulnerability
vendor_ubuntu·2023-11-29·CVSS 7.7
CVE-2022-30790 [HIGH] u-boot-nezha vulnerability
Title: u-boot-nezha vulnerability
Summary: Several security issues were fixed in u-boot-nezha.
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2022-30552, CVE-2022-30790)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
U-Boot vulnerabilities
vendor_ubuntu·2022-12-06·CVSS 7.7
CVE-2022-30767 [HIGH] U-Boot vulnerabilities
Title: U-Boot vulnerabilities
Summary: Several security issues were fixed in u-boot.
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30552, CVE-2022-30790)
It was discovered that U-Boot incorrectly handled certain NFS lookup
replies. A remote attacker could use this iss
Microsoft
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
vendor_msrc·2022-06-14·CVSS 7.8
CVE-2022-30790 [MEDIUM] CWE-787 Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2022-30790: u-boot - Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
vendor_debian·2022·CVSS 5.5
CVE-2022-30790 [MEDIUM] CVE-2022-30790: u-boot - Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
Scope: local
bookworm: resolved (fixed in 2022.07+dfsg-1)
bullseye: resolved (fixed in 2021.01+dfsg-5+deb11u1)
forky: resolved (fixed in 2022.07+dfsg-1)
sid: resolved (fixed in 2022.07+dfsg-1)
trixie: resolved (fixed in 2022.07+dfsg-1)
OSV
u-boot-nezha vulnerability
osv·2023-11-29·CVSS 7.1
CVE-2022-2347 [HIGH] u-boot-nezha vulnerability
u-boot-nezha vulnerability
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2022-30552, CVE-2022-30790)
OSV
u-boot vulnerabilities
osv·2022-12-06·CVSS 7.1
CVE-2022-2347 [HIGH] u-boot vulnerabilities
u-boot vulnerabilities
It was discovered that U-Boot incorrectly handled certain USB DFU download
setup packets. A local attacker could use this issue to cause U-Boot to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2022-2347)
Nicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled
certain fragmented IP packets. A local attacker could use this issue to
cause U-Boot to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu
20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30552, CVE-2022-30790)
It was discovered that U-Boot incorrectly handled certain NFS lookup
replies. A remote attacker could use this issue to cause U-Boot to crash,
resulting in a denial of service,
GHSA
GHSA-mrg2-fqpf-5crp: Das U-Boot 2022
ghsa_unreviewed·2022-06-09·CVSS 5.5
CVE-2022-30790 [MEDIUM] CWE-787 GHSA-mrg2-fqpf-5crp: Das U-Boot 2022
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
OSV
CVE-2022-30790: Das U-Boot 2022
osv·2022-06-08·CVSS 5.5
CVE-2022-30790 [MEDIUM] CVE-2022-30790: Das U-Boot 2022
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
No detection rules found.
No public exploits indexed.
arXiv
Attacker Control and Bug Prioritization
arxiv_cs_cr·2025-03-31
Attacker Control and Bug Prioritization
Attacker Control and Bug Prioritization
As bug-finding methods improve, bug-fixing capabilities are exceeded, resulting in an accumulation of potential vulnerabilities. There is thus a need for efficient and precise bug prioritization based on exploitability. In this work, we explore the notion of control of an attacker over a vulnerability's parameters, which is an often overlooked factor of exploitability. We show that taint as well as straightforward qualitative and quantitative notions of control are not enough to effectively differentiate vulnerabilities. Instead, we propose to focus analysis on feasible value sets, which we call domains of control, in order to better take into account threat models and expert insight. Our new Shrink and Split algorithm efficiently extracts domains o
arXiv
Attacker Control and Bug Prioritization
arxiv_fulltext·2025-03-31
Attacker Control and Bug Prioritization
Attacker Control and Bug Prioritization
Guilhem Lacombe
Université Paris-Saclay, CEA, List, France
[email protected]
Sébastien Bardin
Université Paris-Saclay, CEA, List, France
[email protected]
## Abstract
As bug-finding methods improve, bug-fixing capabilities are exceeded, resulting in an accumulation of potential vulnerabilities.
There is thus a need for efficient and precise bug prioritization based on exploitability.
In this work, we explore the notion of control of an attacker over a vulnerability's parameters, which is an often overlooked factor of exploitability.
We show that taint as well as straightforward qualitative and quantitative notions of control are not enough to effectively differentiate vulnerabilities.
Instead, we propose to focus analysis on
https://github.com/u-boot/u-boot/tagshttps://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/https://github.com/u-boot/u-boot/tagshttps://lists.debian.org/debian-lts-announce/2025/05/msg00001.htmlhttps://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/https://cert-portal.siemens.com/productcert/html/ssa-577017.html
2022-06-08
Published