alsa-2022:5099
Vulnerability from osv_almalinux
The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices. The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments. Security Fix(es): * grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733) * grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695) * grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696) * grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697) * grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734) * grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735) * grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736) * shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-common"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-efi-aa64"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-efi-aa64-cdboot"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-efi-aa64-modules"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-efi-x64"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-efi-x64-cdboot"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-efi-x64-modules"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-pc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-pc-modules"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-ppc64le"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-ppc64le-modules"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-tools"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-tools-efi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-tools-extra"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "grub2-tools-minimal"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:2.06-27.el9_0.7.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "shim-aa64"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "15.6-1.el9.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "shim-unsigned-x64"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "15.6-1.el9.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:9",
"name": "shim-x64"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "15.6-1.el9.alma"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.\nThe shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.\nSecurity Fix(es):\n* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)\n* grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695)\n* grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696)\n* grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697)\n* grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734)\n* grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735)\n* grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736)\n* shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737)\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.",
"id": "ALSA-2022:5099",
"modified": "2022-08-23T18:24:43Z",
"published": "2022-06-16T00:00:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2022:5099"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-3695"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-3696"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2021-3697"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2022-28733"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2022-28734"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2022-28735"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2022-28736"
},
{
"type": "REPORT",
"url": "https://access.redhat.com/security/cve/CVE-2022-28737"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/1991685"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/1991686"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/1991687"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2083339"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2090463"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2090857"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2090899"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/2092613"
},
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/9/ALSA-2022-5099.html"
}
],
"related": [
"CVE-2022-28733",
"CVE-2021-3695",
"CVE-2021-3696",
"CVE-2021-3697",
"CVE-2022-28734",
"CVE-2022-28735",
"CVE-2022-28736",
"CVE-2022-28737"
],
"summary": "Important: grub2, mokutil, shim, and shim-unsigned-x64 security update"
}
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.