Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9: 2024-0095 Critical Grub2 Update for Heap Corruption

mageia
Calendar Grey March 28, 2024
Dist Mageia Esm H88
The recent Grub2 update resolves critical security vulnerabilities, addressing heap overflow and circumvention of authentication in Mageia.
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver

Summary

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved. (CVE-2023-4692) An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk. (CVE-2023-4693) An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attach...

References

- https://bugs.mageia.org/show_bug.cgi?id=32997

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/

- https://www.cve.org/CVERecord?id=CVE-2023-4692

- https://www.cve.org/CVERecord?id=CVE-2023-4693

- https://www.cve.org/CVERecord?id=CVE-2023-4001

- https://www.cve.org/CVERecord?id=CVE-2024-1048

Resolution

SRPMS

- 9/core/grub2-2.06-28.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0095.html
Type: security
CVE: CVE-2023-4692, CVE-2023-4693, CVE-2023-4001, CVE-2024-1048

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here