Search CVE reports
21 – 30 of 57 results
A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 4 of 8
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Fixed | Not affected | Not affected | Not affected |
grub2-signed | Fixed | Not affected | Not affected | Not affected |
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Not affected | Not affected | Not affected | Not affected |
Some fixes available 10 of 16
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Not affected | Fixed | Fixed | Needs evaluation |
grub2-signed | Fixed | Fixed | Fixed | Needs evaluation |
Some fixes available 14 of 19
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Fixed | Fixed | Fixed | Needs evaluation |
grub2-signed | Fixed | Fixed | Fixed | Needs evaluation |
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable...
3 affected packages
grub2, grub2-unsigned, grub2-signed
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-unsigned | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Not affected | Not affected | Not affected | Not affected |