CVE-2022-30552: Das U-Boot 2022.01 has a Buffer Overflow. CVE-2022-30790: Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. According to the advisory, patches exist and were posted to the u-boot mailing list on May 26, but may not be in upstream git yet. There's also been a writeup of the vulnerabilities on that list since May 18. Of course, none of this is referenced by the CVEs.
Original advisory: https://lists.denx.de/pipermail/u-boot/2022-May/484383.html CVE-2022-30767 patch: https://lists.denx.de/pipermail/u-boot/2022-May/484386.html I can't seem to find a patch for the other CVE.
See https://bugs.gentoo.org/856472#c1, this is similar
Thanks!