Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4693
HistoryOct 03, 2023 - 12:00 a.m.

CVE-2023-4693

2023-10-0300:00:00
ubuntu.com
ubuntu.com
11
grub2
ntfs filesystem
out-of-bounds read
attacker
sensitive data
memory
efi variable
confidentiality
risk
secure boot
esm
i386 trusty
ga kernel
key revocation
cwe-125
unix

5.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.6%

An out-of-bounds read flaw was found on grub2’s NTFS filesystem driver.
This issue may allow a physically present attacker to present a specially
crafted NTFS file system image to read arbitrary memory locations. A
successful attack allows sensitive data cached in memory or EFI variable
values to be leaked, presenting a high Confidentiality risk.

Notes

Author Note
eslerm grub2-unsigned contains Secure Boot security fixes the grub2 package unlikely affects Ubuntu’s Secure Boot grub2 and grub2-unsigned should have same major version
eslerm Ubuntu Secure Boot and ESM do not cover i386 trusty’s GA kernel cannot handle new versions of grub Note that key revocation is required to protect against evil housekeeper attacks (such as BlackLotus)
eslerm CWE-125

5.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.6%