发布时间: 2022年11月25日
修改时间: 2024年10月31日
A flaw was found in the grub2 font code. When rendering certain unicode sequences, it fails to properly validate the font width and height. These values are further used to access the font buffer, causing possible out-of-bounds writes. A malicious actor may craft a font capable of triggering this issue, allowing modifications in unauthorized memory segments, causing data integrity problems or leading to denial of service.
NVD | openEuler | |
---|---|---|
Confidentiality | None | None |
Attack Vector | Local | Local |
CVSS评分 | 7.1 | 6.3 |
Attack Complexity | Low | High |
Privileges Required | Low | Low |
Scope | Unchanged | Unchanged |
Integrity | High | High |
User Interaction | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-2732 | grub2 security update | 2022年11月25日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | grub2 | Fixed |
KY3.4-5A | grub2 | Fixed |
KY3.5.1 | grub2 | Fixed |