REDHAT-BUG-2345857: Medium severity GNU GRUB2 vulnerability
When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap Out-of-bounds write, causing data integrity issues and eventually allowing an attacker to circumvent secure boot protections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2345857?
The severity of REDHAT-BUG-2345857 is considered high due to potential data integrity issues and the ability for attackers to circumvent secure boot protections.
How do I fix REDHAT-BUG-2345857?
To fix REDHAT-BUG-2345857, ensure that you apply updates provided by Red Hat for the GNU GRUB2 package that address the vulnerability.
What are the potential consequences of REDHAT-BUG-2345857?
The potential consequences of REDHAT-BUG-2345857 include data integrity issues and unauthorized circumvention of secure boot protections.
Which software is affected by REDHAT-BUG-2345857?
REDHAT-BUG-2345857 affects the GNU GRUB2 bootloader.
Is there a workaround for REDHAT-BUG-2345857?
Currently, there are no officially recommended workarounds for REDHAT-BUG-2345857; applying the fix with updates is advised.