Search CVE reports


Toggle filters

21 – 30 of 57 results


CVE-2024-45778

Medium priority
Needs evaluation

A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2-signed Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45777

Medium priority
Needs evaluation

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2-signed Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45776

Medium priority
Needs evaluation

When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2-signed Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45775

Medium priority
Needs evaluation

A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2-signed Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45774

Medium priority
Needs evaluation

A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grub2-signed Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-2312

Medium priority

Some fixes available 4 of 8

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Fixed Not affected Not affected Not affected
grub2-signed Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-1048

Medium priority
Not affected

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Not affected Not affected Not affected Not affected
grub2-signed Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-4693

Medium priority

Some fixes available 10 of 16

An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Not affected Fixed Fixed Needs evaluation
grub2-signed Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-4692

Medium priority

Some fixes available 14 of 19

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Fixed Fixed Fixed Needs evaluation
grub2-signed Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-4001

Medium priority
Ignored

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable...

3 affected packages

grub2, grub2-unsigned, grub2-signed

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grub2 Not affected Not affected Not affected Not affected
grub2-unsigned Not affected Not affected Not affected Not affected
grub2-signed Not affected Not affected Not affected Not affected
Show less packages