First published: Mon Sep 11 2023(Updated: )
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/grub2 | <2.12~ | 2.12~ |
ubuntu/grub2-unsigned | <2.06-2ubuntu14.4 | 2.06-2ubuntu14.4 |
ubuntu/grub2-unsigned | <2.06-2ubuntu14.4 | 2.06-2ubuntu14.4 |
ubuntu/grub2-unsigned | <2.06-2ubuntu17.2 | 2.06-2ubuntu17.2 |
ubuntu/grub2-signed | <1.187.6~20.04.1 | 1.187.6~20.04.1 |
ubuntu/grub2-signed | <1.187.6 | 1.187.6 |
ubuntu/grub2-signed | <1.193.2 | 1.193.2 |
debian/grub2 | <=2.06-3~deb10u1<=2.06-3~deb11u5<=2.06-13<=2.06-13+deb13u1 | 2.06-3~deb10u4 2.06-3~deb11u6 2.06-13+deb12u1 2.12~rc1-12 |
Gnu Grub2 | ||
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
<2.12 | ||
=8.0 | ||
=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4693 is a vulnerability in grub2 that allows a physically present attacker to read arbitrary memory locations by presenting a specially crafted NTFS file system image.
An attacker can exploit CVE-2023-4693 by leveraging the out-of-bounds read vulnerability in grub2 and presenting a specially crafted NTFS file system image.
The severity of CVE-2023-4693 is high due to the potential for sensitive data leakage and memory access.
The affected software versions include grub2 versions up to and excluding 2.12~, grub2-unsigned versions up to and excluding 2.06-2ubuntu14.4, grub2-unsigned versions up to and excluding 2.06-2ubuntu14.4, grub2-unsigned versions up to and excluding 2.06-2ubuntu17.2, grub2-signed versions up to and excluding 1.187.6~20.04.1, grub2-signed versions up to and excluding 1.187.6, and grub2-signed versions up to and excluding 1.193.2.
To fix CVE-2023-4693, update to grub2 version 2.12~, grub2-unsigned version 2.06-2ubuntu14.4, grub2-unsigned version 2.06-2ubuntu14.4, grub2-unsigned version 2.06-2ubuntu17.2, grub2-signed version 1.187.6~20.04.1, grub2-signed version 1.187.6, or grub2-signed version 1.193.2, depending on the affected software package.