First published: Wed Jun 01 2022(Updated: )
There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free vulnerability is triggered. If an attacker can control the GRUB2's memory allocation pattern sensitive data may be exposed and arbitrary code execution can be achieved.
Credit: security@ubuntu.com security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnu Grub2 | >=2.00<2.06-3 | |
ubuntu/grub2 | <2.06-3 | 2.06-3 |
debian/grub2 | 2.06-3~deb10u1 2.06-3~deb10u3 2.06-3~deb11u5 2.06-3~deb11u4 2.06-13 2.12~rc1-9 | |
redhat/grub2 | <1:2.02-123.el8_6.8 | 1:2.02-123.el8_6.8 |
redhat/grub2 | <1:2.02-87.el8_1.10 | 1:2.02-87.el8_1.10 |
redhat/grub2 | <1:2.02-87.el8_2.10 | 1:2.02-87.el8_2.10 |
redhat/grub2 | <1:2.02-99.el8_4.9 | 1:2.02-99.el8_4.9 |
redhat/grub2 | <1:2.06-27.el9_0.7 | 1:2.06-27.el9_0.7 |
redhat/grub | <2.12 | 2.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-28736 is a use-after-free vulnerability found in the grub2 chainloader command.
The severity of CVE-2022-28736 is high with a CVSS score of 7.8.
CVE-2022-28736 affects the GRUB2 package versions 1:2.02-123.el8_6.8, 1:2.02-87.el8_1.10, 1:2.02-87.el8_2.10, 1:2.02-99.el8_4.9, 1:2.06-27.el9_0.7, and GRUB package version 2.12.
To fix CVE-2022-28736, it is recommended to update the affected GRUB2 package to version 1:2.02-123.el8_6.8, 1:2.02-87.el8_1.10, 1:2.02-87.el8_2.10, 1:2.02-99.el8_4.9, 1:2.06-27.el9_0.7, or update the GRUB package to version 2.12.
More information about CVE-2022-28736 can be found at the following references: [Openwall](https://www.openwall.com/lists/oss-security/2022/06/07/5), [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28736), [CVE](https://www.cve.org/CVERecord?id=CVE-2022-28736), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-28736)