Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-28733

Опубликовано: 20 июл. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

does not affect Secure Boot
esm-infra-legacy/trusty

not-affected

does not affect Secure Boot
esm-infra-legacy/xenial

not-affected

does not affect Secure Boot
esm-infra/bionic

not-affected

does not affect Secure Boot
esm-infra/focal

not-affected

does not affect Secure Boot
esm-infra/xenial

not-affected

does not affect Secure Boot
focal

not-affected

does not affect Secure Boot
impish

ignored

end of life
jammy

not-affected

does not affect Secure Boot

Показывать по

РелизСтатусПримечание
bionic

released

1.187.3~18.04.1
devel

not-affected

1.193
esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needed

esm-infra/bionic

released

1.187.3~18.04.1
esm-infra/focal

released

1.187.3~20.04.1
esm-infra/xenial

ignored

end of ESM support, was needed
focal

released

1.187.3~20.04.1
jammy

released

1.187.3~22.04.1
kinetic

ignored

end of life

Показывать по

РелизСтатусПримечание
bionic

released

2.06-2ubuntu14.1
devel

not-affected

2.06-2ubuntu17
esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

needed

esm-infra/bionic

released

2.06-2ubuntu14.1
esm-infra/focal

released

2.06-2ubuntu14.1
esm-infra/xenial

ignored

end of ESM support, was needed
focal

released

2.06-2ubuntu14.1
jammy

released

2.06-2ubuntu14.1
kinetic

ignored

end of life

Показывать по

EPSS

Процентиль: 67%
0.01284
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
около 4 лет назад

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

CVSS3: 8.1
nvd
около 3 лет назад

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

CVSS3: 8.1
msrc
5 месяцев назад

Integer underflow in grub_net_recv_ip4_packets

CVSS3: 8.1
debian
около 3 лет назад

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP ...

CVSS3: 8.1
github
около 3 лет назад

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

EPSS

Процентиль: 67%
0.01284
Низкий

8.1 High

CVSS3