Mageia 2024-0095: grub2 security update
Summary
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved. (CVE-2023-4692) An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk. (CVE-2023-4693) An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attach...
References
- https://bugs.mageia.org/show_bug.cgi?id=32997
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4692
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4693
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4001
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1048
Resolution
MGASA-2024-0095 - Updated grub2 packages fix security vulnerabilities
SRPMS
- 9/core/grub2-2.06-28.2.mga9