Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29550
HistoryMar 03, 2021 - 5:51 a.m.

Privilege Escalation

2021-03-0305:51:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.0004 Low

EPSS

Percentile

5.1%

grub2 is vulnerable to privilege escalation. The vulnerability exists as variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If the function is called with a command line that references a variable with a sufficiently large payload, it is possible to overflow the stack buffer, corrupt the stack frame and control execution which could also circumvent Secure Boot protections.