4.5

CVE-2021-3695

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Grub2 Version >= 2.00 < 2.12
Fedoraproject ≫ Fedora Version 36
Redhat ≫ Developer Tools Version 1.0
Redhat ≫ Openshift Version 3.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 8.1
Redhat ≫ Enterprise Linux Version 8.4
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 9.0
Redhat ≫ Openshift Container Platform Version 4.6
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.9
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.10
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Codeready Linux Builder Version -
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
   Redhat ≫ Enterprise Linux Eus Version 8.2
   Redhat ≫ Enterprise Linux Eus Version 8.4
   Redhat ≫ Enterprise Linux Eus Version 8.6
   Redhat ≫ Enterprise Linux Eus Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.368
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.5 1 3.4
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://security.gentoo.org/glsa/202209-12
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1991685
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20220930-0001/
Third Party Advisory