CVE-2023-4001
published 2024-01-15CVE-2023-4001: An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the…
PriorityP434medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.54%
41.9th percentile
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 0 < 5.4.0-164.181 | 5.4.0-164.181 |
| msrc | azl3_grub2_2.06-23_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06-13_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-4001: An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains
osv·2024-01-15·CVSS 6.8
CVE-2023-4001 [MEDIUM] CVE-2023-4001: An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
GHSA
GHSA-rr4v-xrwq-7rhx: An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains
ghsa_unreviewed·2024-01-15
CVE-2023-4001 [MEDIUM] CWE-290 GHSA-rr4v-xrwq-7rhx: An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linu
osv·2023-10-04·CVSS 4.1
CVE-2021-4001 linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linu
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities
It was discovered that the eBPF implementation in the Linux kernel
contained a race condition around read-only maps. A privileged attacker
could use this to modify read-only maps. (CVE-2021-4001)
It was discovered that the IPv6 implementation in the Linux kernel
contained a high rate of hash collisions in connection lookup table. A
remote attacker could use this to cause a denial of service (excessive CPU
consumption). (CVE-2023-1206)
Yang Lan discovered that the GFS2 file system implementation in the Linux
kern
Red Hat
grub2: bypass the GRUB password protection feature
vendor_redhat·2024-01-09·CVSS 6.8
CVE-2023-4001 [MEDIUM] CWE-290 grub2: bypass the GRUB password protection feature
grub2: bypass the GRUB password protection feature
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration f
Microsoft
Grub2: bypass the grub password protection feature
vendor_msrc·2024-01-09·CVSS 6.8
CVE-2023-4001 [MEDIUM] CWE-290 Grub2: bypass the grub password protection feature
Grub2: bypass the grub password protection feature
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2023-4001: grub2 - An authentication bypass flaw was found in GRUB due to the way that GRUB uses th...
vendor_debian·2023·CVSS 6.8
CVE-2023-4001 [MEDIUM] CVE-2023-4001: grub2 - An authentication bypass flaw was found in GRUB due to the way that GRUB uses th...
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:0437https://access.redhat.com/errata/RHSA-2024:0456https://access.redhat.com/errata/RHSA-2024:0468https://access.redhat.com/security/cve/CVE-2023-4001https://bugzilla.redhat.com/show_bug.cgi?id=2224951https://dfir.ru/2024/01/15/cve-2023-4001-a-vulnerability-in-the-downstream-grub-boot-manager/http://www.openwall.com/lists/oss-security/2024/01/15/3https://access.redhat.com/errata/RHSA-2024:0437https://access.redhat.com/errata/RHSA-2024:0456https://access.redhat.com/errata/RHSA-2024:0468https://access.redhat.com/security/cve/CVE-2023-4001https://bugzilla.redhat.com/show_bug.cgi?id=2224951https://dfir.ru/2024/01/15/cve-2023-4001-a-vulnerability-in-the-downstream-grub-boot-manager/https://lists.fedoraproject.org/archives/list/[email protected]/message/3OBADMKHQLJOBA32Q7XPNSYMVHVAFDCB/https://lists.fedoraproject.org/archives/list/[email protected]/message/CHLZQ47HM64NDOHMHYO7VIJFYD5ZPPYN/https://security.netapp.com/advisory/ntap-20240216-0006/
2024-01-15
Published