USN-6410-1: GRUB2 vulnerabilities
It was discovered that a specially crafted file system image could cause a heap-based out-of-bounds write. A local attacker could potentially use this to perform arbitrary code execution bypass and bypass secure boot protections. (CVE-2023-4692) It was discovered that a specially crafted file system image could cause an out-of-bounds read. A physically-present attacker could possibly use this to leak sensitive information to the GRUB pager. (CVE-2023-4693)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-6410-1.
What is the severity of USN-6410-1?
The severity of USN-6410-1 is not mentioned.
How does the vulnerability in USN-6410-1 work?
The vulnerability in USN-6410-1 allows a specially crafted file system image to cause a heap-based out-of-bounds write, potentially leading to arbitrary code execution and bypassing secure boot protections.
Which software versions are affected by USN-6410-1?
The affected software versions are Ubuntu 23.04, Ubuntu 22.04, and Ubuntu 20.04.
How can I fix USN-6410-1?
To fix USN-6410-1, you can update the affected packages to the recommended versions mentioned in the advisory.