Grub2 CVE Vulnerabilities
By Gnu — 2 known vulnerabilities
Critical
0
High
2
Medium
0
Low
0
None
0
All Grub2 CVEs
CVE-2022-3775
7.1
high
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and a
Dec 19, 2022
CVE-2022-2601
8.6
high
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker
Dec 14, 2022