Red Hat grub2
cpe:2.3:a:gnu:grub:*:*:*:*:*:*:*, +1 more
A heap out-of-bounds write vulnerability has been identified in GRUB2 when it reads symbolic link names from a UFS filesystem. The issue arises because GRUB2 does not properly validate the length of the input string, leading to potential data integrity problems. This vulnerability could allow an attacker to bypass secure boot protections.
Exploitation of this vulnerability causes a heap-based buffer overflow, which can lead to memory corruption and the potential for arbitrary code execution.
Users can apply the GRUB2 security update available for Red Hat Enterprise Linux 9. Instructions for applying this update can be found in the Red Hat Enterprise Linux 9 Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.