cbcvebase.
CVE-2022-3775
published 2022-12-19

CVE-2022-3775: When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size…

high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiangrub2< grub2 2.06-5 (bookworm)grub2 2.06-5 (bookworm)
gnugrub2<= 2.06
gnugrub2
gnugrub2>= 0 < 2.06-3~deb11u42.06-3~deb11u4
gnugrub2>= 0 < 2.06-52.06-5
gnugrub2>= 0 < 2.06-52.06-5
gnugrub2>= 0 < 2.06-52.06-5
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_21h2
msrcwindows_10_version_22h2
msrcwindows_11_version_21h2
msrcwindows_11_version_22h2
msrcwindows_11_version_23h2
msrcwindows_11_version_24h2
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv7.1HIGH