发布时间: 2022年11月25日
修改时间: 2024年10月31日
A flaw was found where a maliciously crafted pf2 font could lead to an out-of-bounds write in grub2. A successful attack can lead to memory corruption and secure boot circumvention.
NVD | openEuler | |
---|---|---|
Confidentiality | High | High |
Attack Vector | Local | Local |
CVSS评分 | 8.6 | 6.4 |
Attack Complexity | Low | High |
Privileges Required | None | High |
Scope | Changed | Unchanged |
Integrity | High | High |
User Interaction | Required | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-2732 | grub2 security update | 2022年11月25日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | grub2 | Fixed |
KY3.4-5A | grub2 | Fixed |
KY3.5.1 | grub2 | Fixed |