QID 355137

Date Published: 2023-05-29

QID 355137: Amazon Linux Security Advisory for grub2 : ALAS2023-2023-020

a flaw was found in grub 2, where a crafted 16-bit grayscale png image may lead to an out-of-bounds write.
This flaw allows an attacker to corrupt the data on the heap portion of the grub2s memory, leading to possible code execution and the circumvention of the secure boot mechanism. (
( CVE-2021-3695) a flaw was found in grub2 when handling a png image header.
When decoding the data contained in the huffman table at the png file header, an out-of-bounds write may happen on grubs heap. (
( CVE-2021-3696) a flaw was found in grub2 when handling jpeg images.
This flaw allows an attacker to craft a malicious jpeg image, which leads to an underflow on a grub2s internal pointer, leading to a heap-based out-of-bounds write.
Secure-boot mechanisms circumvention and arbitrary code execution may also be achievable. (
( CVE-2021-3697) a flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content.
This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. (
( CVE-2021-3981) a flaw was found where a maliciously crafted pf2 font could lead to an out-of-bounds write in grub2.
A successful attack can lead to memory corruption and secure boot circumvention. (
( CVE-2022-2601) a flaw was found in grub2 when handling ipv4 packets.
This flaw allows an attacker to craft a malicious packet, triggering an integer underflow in grub code.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-020 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-020 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-020.html