Gnu

Grub2

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 06.02.2024 18:15:59
  • Zuletzt bearbeitet 21.11.2024 08:49:40

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the...

  • EPSS 0.04%
  • Veröffentlicht 15.01.2024 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:34:11

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an exte...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 25.10.2023 18:17:41
  • Zuletzt bearbeitet 04.11.2025 20:17:11

An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive ...

Exploit
  • EPSS 0%
  • Veröffentlicht 25.10.2023 18:17:41
  • Zuletzt bearbeitet 04.11.2025 20:17:11

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also cor...

  • EPSS 0.14%
  • Veröffentlicht 20.07.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:49

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, wr...

  • EPSS 0.03%
  • Veröffentlicht 20.07.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:50

There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than onc...

  • EPSS 0.02%
  • Veröffentlicht 20.07.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:49

The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.

  • EPSS 0.11%
  • Veröffentlicht 20.07.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:49

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around...

  • EPSS 0.08%
  • Veröffentlicht 19.12.2022 20:15:11
  • Zuletzt bearbeitet 21.11.2024 07:20:13

When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write int...

  • EPSS 0.06%
  • Veröffentlicht 14.12.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:01:19

A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow...