cbcvebase.
CVE-2022-28733
published 2023-07-20

CVE-2022-28733: Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on…

PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.28%
66.9th percentile
Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiangrub2< grub2 2.06-3 (bookworm)grub2 2.06-3 (bookworm)
gnugrub2>= 0 < 2.06-3~deb11u12.06-3~deb11u1
gnugrub2>= 0 < 2.06-32.06-3
gnugrub2>= 0 < 2.06-32.06-3
gnugrub2>= 0 < 2.06-32.06-3
gnugrub2>= 2.00 < 2.06-32.06-3
gnu_projectgnu_grub< 2.06-32.06-3
msrcazl3_grub2_2.06-14_on_azure_linux_3.0
msrcazl3_grub2_2.06-23_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatshim>= 0 < 15.7-0ubuntu115.7-0ubuntu1
redhatshim>= 0 < 15.7-0ubuntu115.7-0ubuntu1

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.