CVE-2021-3696

Severity
4.5MEDIUM
EPSS
0.1%
top 70.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 6
Latest updateSep 8

Description

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.0 | Impact: 3.4

Affected Packages9 packages

NVDgnu/grub22.002.12
Debiangrub2< 2.06-3~deb11u1+3
Ubuntugrub2-signed< 1.187.3~20.04.1+1
Ubuntugrub2-unsigned< 2.06-2ubuntu14.1+1
CVEListV5grub2grub-2.06

Also affects: Enterprise Linux 8.0, 8.1, 8.4, 9.0, 8.2, 8.6, Openshift Container Platform 4.10, 4.6, 4.9

🔴Vulnerability Details

4
OSV
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability2023-09-08
GHSA
GHSA-mv5h-82v3-mq2x: A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader2022-07-07
CVEList
CVE-2021-3696: A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader2022-07-06
OSV
CVE-2021-3696: A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader2022-07-06

📋Vendor Advisories

4
Ubuntu
GRUB2 vulnerabilities2023-09-08
Microsoft
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality Integrity and Availablity impact may 2022-07-12
Red Hat
grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling2022-06-07
Debian
CVE-2021-3696: grub2 - A heap out-of-bounds write may heppen during the handling of Huffman tables in t...2021