Gnu

Grub2

53 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 06.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:10

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a...

  • EPSS 0.11%
  • Veröffentlicht 06.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:10

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an atta...

  • EPSS 0.06%
  • Veröffentlicht 06.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:10

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.03.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:34:36

A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to...

  • EPSS 0.02%
  • Veröffentlicht 10.03.2022 17:43:14
  • Zuletzt bearbeitet 21.11.2024 06:23:18

A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can even...

  • EPSS 0.06%
  • Veröffentlicht 15.03.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 06:21:27

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could ha...

  • EPSS 0.13%
  • Veröffentlicht 03.03.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:46:10

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters...

  • EPSS 0.03%
  • Veröffentlicht 03.03.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:21:45

A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If t...

  • EPSS 1.45%
  • Veröffentlicht 03.03.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:03:07

A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) cont...

  • EPSS 0.02%
  • Veröffentlicht 03.03.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:18:17

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow ...