Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jpf-4r7j-42qr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

EPSS

Процентиль: 9%
0.00034
Низкий

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.7
ubuntu
почти 5 лет назад

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

CVSS3: 5.7
redhat
почти 5 лет назад

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

CVSS3: 5.7
nvd
почти 5 лет назад

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

CVSS3: 5.7
debian
почти 5 лет назад

There is an issue with grub2 before version 2.06 while handling symlin ...

CVSS3: 5.1
fstec
почти 5 лет назад

Уязвимость загрузчика операционных систем Grub2, связанная с выходом операции за границы буфера данных, позволяющая нарушителю оказать влияние на целостность данных или вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00034
Низкий

Дефекты

CWE-190