Gnu

Grub2

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 19.02.2025 18:15:23
  • Zuletzt bearbeitet 28.07.2025 17:26:10

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2'...

  • EPSS 0.1%
  • Veröffentlicht 29.12.2024 07:15:06
  • Zuletzt bearbeitet 31.12.2024 19:15:48

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

  • EPSS 0.13%
  • Veröffentlicht 29.12.2024 07:15:06
  • Zuletzt bearbeitet 31.12.2024 19:15:48

GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 05.04.2024 20:15:09
  • Zuletzt bearbeitet 26.08.2025 17:17:34

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.

  • EPSS 0.01%
  • Veröffentlicht 06.02.2024 18:15:59
  • Zuletzt bearbeitet 21.11.2024 08:49:40

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the...

  • EPSS 0.03%
  • Veröffentlicht 15.01.2024 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:34:11

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an exte...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 25.10.2023 18:17:41
  • Zuletzt bearbeitet 21.11.2024 08:35:42

An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive ...

Exploit
  • EPSS 0%
  • Veröffentlicht 25.10.2023 18:17:41
  • Zuletzt bearbeitet 21.11.2024 08:35:41

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also cor...

  • EPSS 0.03%
  • Veröffentlicht 20.07.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:50

There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than onc...

  • EPSS 0.02%
  • Veröffentlicht 20.07.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:49

The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.