CVE-2023-4693: Grub2: out-of-bounds read at fs/ntfs.c
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk.
Other sources
There an out-of-bounds read at fs/ntfs.c, a physically present attacker may leverage that by presenting a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack may allow sensitive data cached in memory or EFI variables values to be leaked presenting a high Confidentiality risk.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/grub2to a version that resolves this vulnerability.Fixed in 2.12~ - Upgrade
Upgrade
ubuntu/grub2-unsignedto a version that resolves this vulnerability.Fixed in 2.06-2ubuntu14.4 - Upgrade
Upgrade
ubuntu/grub2-unsignedto a version that resolves this vulnerability.Fixed in 2.06-2ubuntu17.2 - Upgrade
Upgrade
ubuntu/grub2-signedto a version that resolves this vulnerability.Fixed in 1.187.6~20.04.1 - Upgrade
Upgrade
ubuntu/grub2-signedto a version that resolves this vulnerability.Fixed in 1.187.6 - Upgrade
Upgrade
ubuntu/grub2-signedto a version that resolves this vulnerability.Fixed in 1.193.2 - Upgrade
Upgrade
debian/grub2to a version that resolves this vulnerability.Fixed in 2.06-3~deb10u4Fixed in 2.06-3~deb11u6Fixed in 2.06-13+deb12u1Fixed in 2.12~rc1-12
Event History
Frequently Asked Questions
What is CVE-2023-4693?
CVE-2023-4693 is a vulnerability in grub2 that allows a physically present attacker to read arbitrary memory locations by presenting a specially crafted NTFS file system image.
How can an attacker exploit CVE-2023-4693?
An attacker can exploit CVE-2023-4693 by leveraging the out-of-bounds read vulnerability in grub2 and presenting a specially crafted NTFS file system image.
What is the severity of CVE-2023-4693?
The severity of CVE-2023-4693 is high due to the potential for sensitive data leakage and memory access.
Which software versions are affected by CVE-2023-4693?
The affected software versions include grub2 versions up to and excluding 2.12~, grub2-unsigned versions up to and excluding 2.06-2ubuntu14.4, grub2-unsigned versions up to and excluding 2.06-2ubuntu14.4, grub2-unsigned versions up to and excluding 2.06-2ubuntu17.2, grub2-signed versions up to and excluding 1.187.6~20.04.1, grub2-signed versions up to and excluding 1.187.6, and grub2-signed versions up to and excluding 1.193.2.
How can I fix CVE-2023-4693?
To fix CVE-2023-4693, update to grub2 version 2.12~, grub2-unsigned version 2.06-2ubuntu14.4, grub2-unsigned version 2.06-2ubuntu14.4, grub2-unsigned version 2.06-2ubuntu17.2, grub2-signed version 1.187.6~20.04.1, grub2-signed version 1.187.6, or grub2-signed version 1.193.2, depending on the affected software package.