REDHAT-BUG-2346138: Integer Overflow
When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows. A maliciouly crafted filesystem may lead some of those buffer size calculation to overflow, causing it to perform a grubmalloc() operation with a smaller size than expected. As a result the hfsplusopencompressedreal() function will write past of the internal buffer length. This flaw may be leveraged to corrupt grub's internal critical data and may result in arbitrary code execution by-passing secure boot protections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2346138?
The severity of REDHAT-BUG-2346138 has not been explicitly classified in public advisories.
How do I fix REDHAT-BUG-2346138?
To fix REDHAT-BUG-2346138, update to the latest version of GNU GRUB that addresses this vulnerability.
What does REDHAT-BUG-2346138 affect?
REDHAT-BUG-2346138 affects the hfs filesystem module within the GNU GRUB bootloader.
What vulnerability is described in REDHAT-BUG-2346138?
REDHAT-BUG-2346138 describes an integer overflow vulnerability when calculating buffer sizes from user-controlled parameters in hfs filesystem metadata.
Can exploiting REDHAT-BUG-2346138 lead to security issues?
Yes, exploiting REDHAT-BUG-2346138 could lead to potential security issues such as arbitrary code execution or system crashes.