First published: Thu Aug 31 2023(Updated: )
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/grub2 | <2.12~ | 2.12~ |
ubuntu/grub2-unsigned | <2.06-2ubuntu14.4 | 2.06-2ubuntu14.4 |
ubuntu/grub2-unsigned | <2.06-2ubuntu14.4 | 2.06-2ubuntu14.4 |
ubuntu/grub2-unsigned | <2.06-2ubuntu17.2 | 2.06-2ubuntu17.2 |
ubuntu/grub2-signed | <1.187.6~20.04.1 | 1.187.6~20.04.1 |
ubuntu/grub2-signed | <1.187.6 | 1.187.6 |
ubuntu/grub2-signed | <1.193.2 | 1.193.2 |
debian/grub2 | <=2.06-3~deb10u1<=2.06-3~deb11u5<=2.06-13<=2.06-13+deb13u1 | 2.06-3~deb10u4 2.06-3~deb11u6 2.06-13+deb12u1 2.12~rc1-12 |
Gnu Grub2 | ||
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Gnu Grub2 | <2.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4692 is a vulnerability in grub2 that allows an attacker to perform out-of-bounds write/read via a specially crafted NTFS filesystem.
An attacker can exploit this vulnerability by presenting a specially crafted NTFS filesystem image, causing heap metadata corruption in grub and potentially the UEFI firmware heap metadata.
The affected software versions include grub2 2.12~ and earlier, grub2-unsigned 2.06-2ubuntu14.4, grub2-unsigned 2.06-2ubuntu17.2, grub2-signed 1.187.6~20.04.1, and grub2-signed 1.193.2.
To fix CVE-2023-4692, upgrade to grub2 version 2.12~ or later, grub2-unsigned version 2.06-2ubuntu14.4 or later, grub2-unsigned version 2.06-2ubuntu17.2 or later, grub2-signed version 1.187.6~20.04.1 or later, or grub2-signed version 1.193.2 or later.
You can find more information about CVE-2023-4692 on the MITRE CVE website, the GNU GRUB-devel mailing list, and the Ubuntu Security Notices.