CVE-2022-28736: There's a use-after-free vulnerability in grub_cmd_chainloader() function
A use-after-free vulnerability was found on grub2's chainloader command. This flaw allows an attacker to gain access to restricted data or cause arbitrary code execution if they can establish control from grub's memory allocation pattern.
Other sources
There's a use-after-free vulnerability in grubcmdchainloader() function
— Microsoft
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-28736?
CVE-2022-28736 is a use-after-free vulnerability found in the grub2 chainloader command.
What is the severity of CVE-2022-28736?
The severity of CVE-2022-28736 is high with a CVSS score of 7.8.
How does CVE-2022-28736 affect the affected software?
CVE-2022-28736 affects the GRUB2 package versions 1:2.02-123.el8_6.8, 1:2.02-87.el8_1.10, 1:2.02-87.el8_2.10, 1:2.02-99.el8_4.9, 1:2.06-27.el9_0.7, and GRUB package version 2.12.
How can I fix CVE-2022-28736?
To fix CVE-2022-28736, it is recommended to update the affected GRUB2 package to version 1:2.02-123.el8_6.8, 1:2.02-87.el8_1.10, 1:2.02-87.el8_2.10, 1:2.02-99.el8_4.9, 1:2.06-27.el9_0.7, or update the GRUB package to version 2.12.
Where can I find more information about CVE-2022-28736?
More information about CVE-2022-28736 can be found at the following references: [Openwall](https://www.openwall.com/lists/oss-security/2022/06/07/5), [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28736), [CVE](https://www.cve.org/CVERecord?id=CVE-2022-28736), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-28736)