nfslookupreply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"26433567509784795861491119420591390178",
"139851264388448427586386885273476681982",
"102566397628219876016957460735237255863",
"10464583766473143428314599776778313463",
"250100618551608620223203281115845299151",
"220106819974186756061365701647976297066",
"291421002495152642350750009756020206005",
"73407787953136352830763228951237775210",
"178207664579366023471673552940890338857"
]
},
"signature_type": "Line",
"target": {
"file": "net/nfs.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/u-boot/u-boot/commit/5d14ee4e53a81055d34ba280cb8fd90330f22a96",
"id": "CVE-2022-30767-357a11fe"
},
{
"digest": {
"function_hash": "301104250594287063405529259447799514173",
"length": 1847.0
},
"signature_type": "Function",
"target": {
"function": "nfs_lookup_reply",
"file": "net/nfs.c"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/u-boot/u-boot/commit/5d14ee4e53a81055d34ba280cb8fd90330f22a96",
"id": "CVE-2022-30767-9cd6cc4d"
}
]