Back

HIGH

grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap

Published Jul 6, 2022

Description

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

Affected products

Remediation

Red Hat statement

Due to the nature of the input and how it's processed, a successful attack is considered very complex to be executed, as the same value is written out of bounds three times in a row.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 6, 2022
Updated Aug 3, 2024
Reserved Aug 10, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 7, 2022