A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2021-03-03 17:15
Updated : 2021-05-01 02:15
NVD link : CVE-2021-20225
Mitre link : CVE-2021-20225
JSON object : View
Products Affected
redhat
- enterprise_linux_server_tus
- enterprise_linux_workstation
- enterprise_linux_server_aus
- enterprise_linux
- enterprise_linux_server_eus
fedoraproject
- fedora
gnu
- grub2
CWE
CWE-787
Out-of-bounds Write
