First published: Mon Feb 08 2021(Updated: )
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grub | <2.06 | 2.06 |
Gnu Grub2 | <2.06 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Server Aus | =7.2 | |
Redhat Enterprise Linux Server Aus | =7.3 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Aus | =7.7 | |
Redhat Enterprise Linux Server Aus | =8.2 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.7 | |
Redhat Enterprise Linux Server Eus | =8.1 | |
Redhat Enterprise Linux Server Tus | =7.4 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.7 | |
Redhat Enterprise Linux Server Tus | =8.2 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
NetApp ONTAP Select Deploy administration utility |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20233 is a vulnerability found in grub2 versions prior to 2.06.
The severity of CVE-2021-20233 is high with a severity value of 8.2.
The following software is affected by CVE-2021-20233: grub2 versions prior to 2.06, Gnu Grub2, Redhat Enterprise Linux, and other related distributions.
An attacker can exploit CVE-2021-20233 by corrupting memory through a length calculation error in the menu rendering code of grub2.
You can find more information about CVE-2021-20233 on the following references: [1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1927436), [2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1934252), [3](https://access.redhat.com/errata/RHSA-2021:0698).