Out-of-Bounds Write Vulnerability in Grub2 by Red Hat
CVE-2021-3695
4.5MEDIUM
What is CVE-2021-3695?
An out-of-bounds write vulnerability exists in Grub2 due to handling crafted 16-bit grayscale PNG images. This flaw allows attackers to potentially corrupt heap data, leading to severe consequences such as arbitrary code execution and the bypassing of secure boot protections. Exploiting this vulnerability is a complex task, requiring knowledge of the heap layout to manipulate memory effectively. Additionally, the payloads written into memory are repeated multiple times, complicating the exploitation process.
Affected Version(s)
grub2 grub-2.06