Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-3775
HistoryDec 19, 2022 - 12:00 a.m.

CVE-2022-3775

2022-12-1900:00:00
ubuntu.com
ubuntu.com
17
grub2
unicode sequences
memory corruption
availability issues
out-of-bounds write
security fixes
secure boot
key revocation
evil housekeeper attacks

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

When rendering certain unicode sequences, grub2’s font code doesn’t proper
validate if the informed glyph’s width and height is constrained within
bitmap size. As consequence an attacker can craft an input which will lead
to a out-of-bounds write into grub2’s heap, leading to memory corruption
and availability issues. Although complex, arbitrary code execution could
not be discarded.

Bugs

Notes

Author Note
eslerm grub2-unsigned contains Secure Boot security fixes the grub2 package unlikely affects Ubuntu’s Secure Boot grub2 and grub2-unsigned should have same major version Ubuntu Secure Boot and ESM do not cover i386 trusty’s GA kernel cannot handle new versions of grub
eslerm Note that key revocation is required to protect against evil housekeeper attacks (such as BlackLotus)

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%