CVE-2021-3697: High severity centos grub2-pc-modules vulnerability
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
Other sources
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention.
— Red Hat
A flaw was found in grub2 when handling JPEG images. This flaw allows an attacker to craft a malicious JPEG image, which leads to an underflow on a grub2's internal pointer, leading to a heap-based out-of-bounds write. Secure-boot mechanisms circumvention and arbitrary code execution may also be achievable.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3697?
CVE-2021-3697 is a vulnerability in grub2 that allows an attacker to craft a malicious JPEG image, leading to a heap underflow and potential remote code execution.
How can an attacker exploit CVE-2021-3697?
An attacker can exploit CVE-2021-3697 by creating a specially crafted JPEG image that triggers a heap underflow when processed by the grub2 JPEG reader, allowing them to execute arbitrary code.
Which software versions are affected by CVE-2021-3697?
CVE-2021-3697 affects grub2 versions up to, but not including, 2.12.
How can I fix CVE-2021-3697?
To fix CVE-2021-3697, you should update your grub2 package to version 2.12 or later, as provided by the respective vendor's patch or security advisory.
What is the severity of CVE-2021-3697?
CVE-2021-3697 has a severity rating of high, with a CVSSv3 base score of 7.0.