First published: Mon Oct 31 2022(Updated: )
Redhat: CVE-2022-3775 grub2 - Heap based out-of-bounds write when rendering certain Unicode sequences
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/grub2-unsigned | <2.06-2ubuntu15 | 2.06-2ubuntu15 |
ubuntu/grub2 | <2.06-5 | 2.06-5 |
ubuntu/grub2 | <2.06-2ubuntu14 | 2.06-2ubuntu14 |
debian/grub2 | <=2.06-3~deb10u1 | 2.06-3~deb10u3 2.06-3~deb11u5 2.06-3~deb11u4 2.06-13 2.12~rc1-9 |
redhat/grub | <2.06 | 2.06 |
Microsoft Azure Linux 3.0 x64 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 11 | =24H2 | |
Microsoft Windows 10 | ||
Microsoft Azure Linux 3.0 ARM | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 11 | =24H2 | |
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows Server 2016 | ||
Gnu Grub2 | <=2.06 | |
Red Hat Enterprise Linux | =8.0 | |
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2012 x64 | ||
Microsoft CBL-Mariner | ||
Microsoft CBL-Mariner | ||
Microsoft CBL-Mariner | ||
Microsoft CBL-Mariner | ||
Microsoft Windows Server 2022 23H2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3775 is a vulnerability in grub2's font code that allows an attacker to craft input leading to an out-of-bounds write into grub2's heap, leading to memory corruption.
The affected software includes grub2-unsigned version 2.06-2ubuntu15, grub2 versions up to 2.06-5, and grub2 versions up to 2.06-2ubuntu14.
To fix CVE-2022-3775, update the affected software to grub2-unsigned version 2.06-2ubuntu15, grub2 version 2.06-5, or grub2 version 2.06-2ubuntu14.
You can find more information about CVE-2022-3775 on the MITRE CVE website, the GNU GRUB mailing list, and the NIST National Vulnerability Database (NVD) website.