CVE-2022-2601
Summary
| CVE | CVE-2022-2601 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-14 21:15:00 UTC |
| Updated | 2023-11-25 12:15:00 UTC |
| Description | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism. |
Risk And Classification
Problem Types: CWE-122
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2112975 – (CVE-2022-2601) CVE-2022-2601 grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass | MISC | bugzilla.redhat.com | |
| GRUB: Multiple Vulnerabilities (GLSA 202311-14) — Gentoo security | security.gentoo.org | ||
| CVE-2022-2601 Grub2 Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160386 Oracle Enterprise Linux Security Update for grub2 (ELSA-2023-12019)
- 160437 Oracle Enterprise Linux Security Update for grub2 (ELSA-2023-0049)
- 160730 Oracle Enterprise Linux Security Update for grub2 (ELSA-2023-0752)
- 181216 Debian Security Update for grub2 (DSA 5280-1)
- 181218 Debian Security Update for grub2 (DLA 3190-1)
- 181312 Debian Security Update for grub2 (DLA 3190-2)
- 184689 Debian Security Update for grub2 (CVE-2022-2601)
- 241007 Red Hat Update for grub2 (RHSA-2022:8978)
- 241037 Red Hat Update for grub2 (RHSA-2023:0047)
- 241040 Red Hat Update for grub2 (RHSA-2023:0048)
- 241042 Red Hat Update for grub2 (RHSA-2023:0049)
- 241185 Red Hat Update for grub2 (RHSA-2023:0752)
- 283350 Fedora Security Update for grub2 (FEDORA-2022-f86e203baf)
- 283365 Fedora Security Update for grub2 (FEDORA-2022-7ce9378e90)
- 283416 Fedora Security Update for grub2 (FEDORA-2022-dec4cdacd7)
- 355137 Amazon Linux Security Advisory for grub2 : ALAS2023-2023-020
- 355617 Amazon Linux Security Advisory for grub2 : ALAS2-2023-2146
- 377900 Alibaba Cloud Linux Security Update for grub2 (ALINUX3-SA-2023:0003)
- 672578 EulerOS Security Update for grub2 (EulerOS-SA-2023-1317)
- 672656 EulerOS Security Update for grub2 (EulerOS-SA-2023-1386)
- 672662 EulerOS Security Update for grub2 (EulerOS-SA-2023-1358)
- 672671 EulerOS Security Update for grub2 (EulerOS-SA-2023-1407)
- 672693 EulerOS Security Update for grub2 (EulerOS-SA-2023-1422)
- 672717 EulerOS Security Update for grub2 (EulerOS-SA-2023-1443)
- 672766 EulerOS Security Update for grub2 (EulerOS-SA-2023-1468)
- 710796 Gentoo Linux GRUB Multiple Vulnerabilities (GLSA 202311-14)
- 752845 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:4219-1)
- 752900 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:4218-1)
- 752909 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:4141-1)
- 752923 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:4140-1)
- 752932 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:4142-1)
- 752964 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:4302-1)
- 904689 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (11629)
- 904696 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (11604)
- 905183 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (11629-1)
- 905244 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (11604-1)
- 940866 AlmaLinux Security Update for grub2 (ALSA-2023:0049)
- 940924 AlmaLinux Security Update for grub2 (ALSA-2023:0752)
- 960514 Rocky Linux Security Update for grub2 (RLSA-2023:0049)
- 960577 Rocky Linux Security Update for grub2 (RLSA-2023:0752)