Описание
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
A flaw was found in the HFS file system driver in grub2. This issue allows a local attacker to trigger a heap-based buffer overflow via a specially crafted sblock in a malicious HFS file system, causing memory corruption, unexpected behavior, and denial of service.
Отчет
To exploit this flaw, an attacker needs to trick a user into running grub2 with a specially crafted HFS file system image, limiting the exposure of this flaw. For this reason, this vulnerability has been rated with a Moderate severity. The grub2 package as shipped in Red Hat Enterprise Linux 7, 8, 9 and in Red Hat OpenShift Container Platform 4 is not affected by this vulnerability because the HFS module is not built, so this issue is not applicable.
Меры по смягчению последствий
Do not run grub2 in an untrusted environment, specifically with a HFS file system image.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 10 | grub2 | Not affected | ||
Red Hat Enterprise Linux 7 | grub2 | Not affected | ||
Red Hat Enterprise Linux 8 | grub2 | Not affected | ||
Red Hat Enterprise Linux 9 | grub2 | Not affected | ||
Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in ...
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
Уязвимость компонента HFS File System Handler загрузчика операционных систем Grub (Grub2), позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации
EPSS
7.8 High
CVSS3