Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: grub #1199

Closed
dongsupark opened this issue Oct 6, 2023 · 0 comments · Fixed by flatcar/scripts#1264
Closed

update: grub #1199

dongsupark opened this issue Oct 6, 2023 · 0 comments · Fixed by flatcar/scripts#1264
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Oct 6, 2023

Name: grub
CVEs: CVE-2023-4692, CVE-2023-4693
CVSSs: 7.8, 4.6
Action Needed: update to >= 2.06-r9

Summary:

  • CVE-2023-4692: There is an out-of-bounds write in grub-core/fs/ntfs.c. An attacker may leverage this vulnerability by presenting a specially crafted NTFS filesystem image leading to GRUB's heap metadata corruption. Additionally, in some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result arbitrary code execution and secure boot protection bypass may be achieved.
  • CVE-2023-4693: There is an out-of-bounds read at grub-core/fs/ntfs.c. A physically present attacker may leverage that by presenting a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack may allow sensitive data cached in memory or EFI variables values to be leaked presenting a high confidentiality risk.

refmap.gentoo: https://bugs.gentoo.org/915131

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant