RHSA-2022:5100HighCVSS 8.1
Red Hat Security Advisory: grub2, mokutil, shim, and shim-unsigned-x64 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2021-3695 — grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap CVE-2021-3696 — grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling CVE-2021-3697 — grub2: Crafted JPEG image can lead to buffer underflow write in the heap CVE-2022-28733 — grub2: Integer underflow in grub_net_recv_ip4_packets CVE-2022-28734 — grub2: Out-of-bound write when handling split HTTP headers CVE-2022-28735 — grub2: shim_lock verifier allows non-kernel files to be loaded CVE-2022-28736 — grub2: use-after-free in grub_cmd_chainloader() CVE-2022-28737 — shim: Buffer overflow when loading crafted EFI images
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2022:5100
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991685
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991686
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991687
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090899
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092613
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5100.json