CVE-2023-4692: Grub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code execution
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Other sources
Grub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code execution
— Microsoft
There is an out-of-bounds write in fs/ntfs.c, an attacker may leverage this vulnerability by presenting a specially crafted NTFS filesystem image leading to grub's heap metadata corruption. Additionally, in some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result arbitrary code execution and secure boot protection bypass may be achieved.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/grub2to a version that resolves this vulnerability.Fixed in 2.12~ - Upgrade
Upgrade
ubuntu/grub2-unsignedto a version that resolves this vulnerability.Fixed in 2.06-2ubuntu14.4 - Upgrade
Upgrade
ubuntu/grub2-unsignedto a version that resolves this vulnerability.Fixed in 2.06-2ubuntu17.2 - Upgrade
Upgrade
ubuntu/grub2-signedto a version that resolves this vulnerability.Fixed in 1.187.6~20.04.1 - Upgrade
Upgrade
ubuntu/grub2-signedto a version that resolves this vulnerability.Fixed in 1.187.6 - Upgrade
Upgrade
ubuntu/grub2-signedto a version that resolves this vulnerability.Fixed in 1.193.2 - Upgrade
Upgrade
debian/grub2to a version that resolves this vulnerability.Fixed in 2.06-3~deb10u4Fixed in 2.06-3~deb11u6Fixed in 2.06-13+deb12u1Fixed in 2.12~rc1-12
Event History
Frequently Asked Questions
What is CVE-2023-4692?
CVE-2023-4692 is a vulnerability in grub2 that allows an attacker to perform out-of-bounds write/read via a specially crafted NTFS filesystem.
How does CVE-2023-4692 work?
An attacker can exploit this vulnerability by presenting a specially crafted NTFS filesystem image, causing heap metadata corruption in grub and potentially the UEFI firmware heap metadata.
Which software versions are affected by CVE-2023-4692?
The affected software versions include grub2 2.12~ and earlier, grub2-unsigned 2.06-2ubuntu14.4, grub2-unsigned 2.06-2ubuntu17.2, grub2-signed 1.187.6~20.04.1, and grub2-signed 1.193.2.
How can I fix CVE-2023-4692?
To fix CVE-2023-4692, upgrade to grub2 version 2.12~ or later, grub2-unsigned version 2.06-2ubuntu14.4 or later, grub2-unsigned version 2.06-2ubuntu17.2 or later, grub2-signed version 1.187.6~20.04.1 or later, or grub2-signed version 1.193.2 or later.
Where can I find more information about CVE-2023-4692?
You can find more information about CVE-2023-4692 on the MITRE CVE website, the GNU GRUB-devel mailing list, and the Ubuntu Security Notices.