A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1926263 | Issue Tracking Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ | |
https://security.gentoo.org/glsa/202104-05 | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20220325-0001/ | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1926263 | Issue Tracking Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ | |
https://security.gentoo.org/glsa/202104-05 | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20220325-0001/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 05:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1926263 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ - | |
References | () https://security.gentoo.org/glsa/202104-05 - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20220325-0001/ - Third Party Advisory |
18 Apr 2022, 19:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* |
|
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20220325-0001/ - Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ - Mailing List, Third Party Advisory | |
References | (GENTOO) https://security.gentoo.org/glsa/202104-05 - Third Party Advisory |
25 Mar 2022, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2021-03-03 17:15
Updated : 2024-11-21 05:46
NVD link : CVE-2021-20233
Mitre link : CVE-2021-20233
CVE.ORG link : CVE-2021-20233
JSON object : View
Products Affected
fedoraproject
- fedora
redhat
- enterprise_linux
- enterprise_linux_server_eus
- enterprise_linux_workstation
- enterprise_linux_server_aus
- enterprise_linux_server_tus
netapp
- ontap_select_deploy_administration_utility
gnu
- grub2
CWE
CWE-787
Out-of-bounds Write