First published: Fri Feb 14 2025(Updated: )
There's an integer overflow in the BFS file system driver. When reading a file with indirect extent map grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause a integer overflow during the file reading, leading to a Heap Ouf-of-Bounds read. As consequence sensitive data may be leaked or the grub2 to crash.
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu GRUB (GNU GRand Unified Bootloader) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2345854 is high due to the potential for a heap out-of-bounds read.
To fix REDHAT-BUG-2345854, update to the latest version of the GNU GRUB that addresses this integer overflow vulnerability.
REDHAT-BUG-2345854 is caused by an integer overflow in the BFS file system driver when reading file entries.
Affected versions of GRUB include any that utilize the BFS file system driver with the integer overflow issue.
The potential impacts of REDHAT-BUG-2345854 include system instability and unauthorized access to system memory.