GNU GRUB
cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*
A heap-based buffer overflow vulnerability has been identified in the UDF filesystem module of GNU GRUB. This issue arises when the module reads data from disk and uses user-controlled data length metadata to allocate internal buffers. In some cases, while processing disk sectors, the module incorrectly assumes that the read size will always be smaller than the allocated buffer size, a condition that cannot be guaranteed. A maliciously crafted filesystem image could exploit this flaw, leading to corruption of critical data and creating a risk of arbitrary code execution that bypasses secure boot protections.
Exploitation of this vulnerability can cause a heap-based buffer overflow, allowing for arbitrary code execution and bypassing secure boot protections.
Updated GRUB2, shim, and other boot artifacts from all affected vendors will be available when the embargo lifts or shortly thereafter. Instructions for applying the latest SBAT revocations can be found in the SBAT documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.