https://seclists.org/oss-sec/2023/q4/40: CVE-2023-4692, CVE-2023-4693: grub2: OOB write, read via specially crafted NTFS filesystem
Published Oct 4, 2023
·Updated
Affected Software
1 affected component
GNU GRUB2
Frequently Asked Questions
1
What is the severity of CVE-2023-4692 and CVE-2023-4693?
CVE-2023-4692 and CVE-2023-4693 are considered high severity vulnerabilities affecting GNU GRUB2.
2
How do I fix CVE-2023-4692 and CVE-2023-4693?
To fix CVE-2023-4692 and CVE-2023-4693, you should upgrade to the patched version of GNU GRUB2 provided by your distribution.
3
What types of attacks are possible due to CVE-2023-4692 and CVE-2023-4693?
CVE-2023-4692 and CVE-2023-4693 can lead to out-of-bounds write and read vulnerabilities through specially crafted NTFS filesystems.
4
Which systems are affected by CVE-2023-4692 and CVE-2023-4693?
Systems running vulnerable versions of GNU GRUB2 with Secure Boot enabled are at risk from CVE-2023-4692 and CVE-2023-4693.
5
When were CVE-2023-4692 and CVE-2023-4693 published?
CVE-2023-4692 and CVE-2023-4693 were published on October 4, 2023.