Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-28736
HistoryJul 20, 2023 - 12:00 a.m.

CVE-2022-28736

2023-07-2000:00:00
ubuntu.com
ubuntu.com
15
vulnerability
grub_cmd_chainloader
use-after-free
chainloader
operating systems
multiboot
grub2
memory allocation
sensitive data
code execution
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.8%

There’s a use-after-free vulnerability in grub_cmd_chainloader() function;
The chainloader command is used to boot up operating systems that doesn’t
support multiboot and do not have direct support from GRUB2. When executing
chainloader more than once a use-after-free vulnerability is triggered. If
an attacker can control the GRUB2’s memory allocation pattern sensitive
data may be exposed and arbitrary code execution can be achieved.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.8%