CVE-2022-28734
published 2023-07-20CVE-2022-28734: Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by…
PriorityP338high7CVSS 3.1
AVNACHPRNUINSUCLILAH
EPSS
1.13%
62.8th percentile
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.06-3 (bookworm) | grub2 2.06-3 (bookworm) |
| gnu | grub2 | >= 0 < 2.06-3~deb11u1 | 2.06-3~deb11u1 |
| gnu | grub2 | >= 0 < 2.06-3 | 2.06-3 |
| gnu | grub2 | >= 0 < 2.06-3 | 2.06-3 |
| gnu | grub2 | >= 0 < 2.06-3 | 2.06-3 |
| gnu | grub2 | >= 2.00 < 2.06-3 | 2.06-3 |
| gnu_project | gnu_grub | < 2.06-3 | 2.06-3 |
| msrc | azl3_grub2_2.06-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-23_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | shim | >= 0 < 15.7-0ubuntu1 | 15.7-0ubuntu1 |
| redhat | shim | >= 0 < 15.7-0ubuntu1 | 15.7-0ubuntu1 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
osv7.0HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_msrc7.0HIGH
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
osv·2023-09-08·CVSS 4.5
CVE-2021-3695 [MEDIUM] grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
Daniel Axtens discovered that specially crafted images could cause a
heap-based out-of-bonds write. A local attacker could possibly use
this to circumvent secure boot protections. (CVE-2021-3695)
Daniel Axtens discovered that specially crafted images could cause
out-of-bonds read and write. A local attacker could possibly use this
to circumvent secure boot protections. (CVE-2021-3696)
Daniel Axtens discovered that specially crafted images could cause
buffer underwrite which allows arbitrary data to be written to a heap.
A local attacker could possibly use this to circumvent secure
boot protections. (CVE-2021-3697)
It was discovered that GRUB2 configuration files were created with
the wrong permissions. An attacker could
OSV
CVE-2022-28734: Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer po
osv·2023-07-20·CVSS 7.0
CVE-2022-28734 [HIGH] CVE-2022-28734: Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer po
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.
GHSA
GHSA-h8v2-pvw7-3jf5: Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer po
ghsa_unreviewed·2023-07-20
CVE-2022-28734 [HIGH] CWE-787 GHSA-h8v2-pvw7-3jf5: Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer po
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.
Ubuntu
GRUB2 vulnerabilities
vendor_ubuntu·2023-09-08·CVSS 4.5
CVE-2022-28737 [MEDIUM] GRUB2 vulnerabilities
Title: GRUB2 vulnerabilities
Summary: Several security issues were fixed in GRUB2.
Daniel Axtens discovered that specially crafted images could cause a
heap-based out-of-bonds write. A local attacker could possibly use
this to circumvent secure boot protections. (CVE-2021-3695)
Daniel Axtens discovered that specially crafted images could cause
out-of-bonds read and write. A local attacker could possibly use this
to circumvent secure boot protections. (CVE-2021-3696)
Daniel Axtens discovered that specially crafted images could cause
buffer underwrite which allows arbitrary data to be written to a heap.
A local attacker could possibly use this to circumvent secure
boot protections. (CVE-2021-3697)
It was discovered that GRUB2 configuration files were created with
the wrong permissions.
Microsoft
Out-of-bounds write when handling split HTTP headers
vendor_msrc·2023-07-11·CVSS 7.0
CVE-2022-28734 [HIGH] CWE-787 Out-of-bounds write when handling split HTTP headers
Out-of-bounds write when handling split HTTP headers
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://
Red Hat
grub2: Out-of-bound write when handling split HTTP headers
vendor_redhat·2022-06-07·CVSS 8.1
CVE-2022-28734 [HIGH] CWE-787 grub2: Out-of-bound write when handling split HTTP headers
grub2: Out-of-bound write when handling split HTTP headers
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.
A flaw was found in grub2 when handling split HTTP headers. While processing a split HTTP header, grub2 wrongly advances its control pointer to the internal buffer by one position, which can lead to an out-of-bounds write. This flaw allows an attacker to leverage this issue by crafting a malicious set of HTTP packages making gru
Debian
CVE-2022-28734: grub2 - Out-of-bounds write when handling split HTTP headers; When handling split HTTP h...
vendor_debian·2022·CVSS 8.1
CVE-2022-28734 [HIGH] CVE-2022-28734: grub2 - Out-of-bounds write when handling split HTTP headers; When handling split HTTP h...
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.
Scope: local
bookworm: resolved (fixed in 2.06-3)
bullseye: resolved (fixed in 2.06-3~deb11u1)
forky: resolved (fixed in 2.06-3)
sid: resolved (fixed in 2.06-3)
trixie: resolved (fixed in 2.06-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28734https://security.netapp.com/advisory/ntap-20230825-0002/https://www.openwall.com/lists/oss-security/2022/06/07/5https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28734https://security.netapp.com/advisory/ntap-20230825-0002/https://www.openwall.com/lists/oss-security/2022/06/07/5
2023-07-20
Published