CVE-2021-3697
Summary
| CVE | CVE-2021-3697 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-06 16:15:00 UTC |
| Updated | 2023-09-13 16:15:00 UTC |
| Description | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1991687 – (CVE-2021-3697) CVE-2021-3697 grub2: Crafted JPEG image can lead to buffer underflow write in the heap | MISC | bugzilla.redhat.com | |
| July 2022 Grub Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| GRUB: Multiple Vulnerabilities (GLSA 202209-12) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159883 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9471)
- 159884 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9469)
- 159943 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-5099)
- 159967 Oracle Enterprise Linux Security Update for grub2, mokutil, shim, and shim-unsigned-x64 (ELSA-2022-5095)
- 159985 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9596)
- 159986 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9595)
- 161027 Oracle Enterprise Linux Security Update for grub2 (ELSA-2023-12952)
- 181012 Debian Security Update for grub2 (CVE-2021-3697)
- 240473 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5100)
- 240474 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5099)
- 240476 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5096)
- 240477 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5095)
- 282811 Fedora Security Update for grub2 (FEDORA-2022-27932fdd06)
- 282866 Fedora Security Update for grub2 (FEDORA-2022-9b4f9af4ce)
- 354332 Amazon Linux Security Advisory for grub2 : ALAS2022-2022-109
- 354535 Amazon Linux Security Advisory for grub2 : ALAS-2022-109
- 355137 Amazon Linux Security Advisory for grub2 : ALAS2023-2023-020
- 355617 Amazon Linux Security Advisory for grub2 : ALAS2-2023-2146
- 377130 Alibaba Cloud Linux Security Update for grub2, mokutil, shim, and shim-unsigned-x64 (ALINUX3-SA-2022:0134)
- 377622 Alibaba Cloud Linux Security Update for grub2, mokutil, shim, and shim-unsigned-x64 (ALINUX3-SA-2022:0164)
- 503017 Alpine Linux Security Update for grub
- 503110 Alpine Linux Security Update for grub
- 503684 Alpine Linux Security Update for grub
- 505876 Alpine Linux Security Update for grub
- 672021 EulerOS Security Update for grub2 (EulerOS-SA-2022-2242)
- 672026 EulerOS Security Update for grub2 (EulerOS-SA-2022-2221)
- 672031 EulerOS Security Update for grub2 (EulerOS-SA-2022-2255)
- 672109 EulerOS Security Update for grub2 (EulerOS-SA-2022-2318)
- 672131 EulerOS Security Update for grub2 (EulerOS-SA-2022-2289)
- 710619 Gentoo Linux GRUB Multiple Vulnerabilities (GLSA 202209-12)
- 752214 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2037-1)
- 752215 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2041-1)
- 752216 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2036-1)
- 752217 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2035-1)
- 752218 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2038-1)
- 752221 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2064-1)
- 752229 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2074-1)
- 907555 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (31036-1)
- 940639 AlmaLinux Security Update for grub2, (ALSA-2022:5095)
- 940640 AlmaLinux Security Update for grub2, (ALSA-2022:5099)
- 960155 Rocky Linux Security Update for grub2, (RLSA-2022:5095)
- 960538 Rocky Linux Security Update for grub2, (RLSA-2022:5099)