CVE-2021-3697
06.07.2022, 16:15
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.Enginsight
Vendor | Product | Version |
---|---|---|
gnu | grub2 | 2.00 ≤ 𝑥 < 2.12 |
redhat | developer_tools | 1.0 |
redhat | openshift | 3.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 8.1 |
redhat | enterprise_linux | 8.4 |
redhat | enterprise_linux | 9.0 |
redhat | enterprise_linux_eus | 8.2 |
redhat | enterprise_linux_eus | 8.4 |
redhat | enterprise_linux_eus | 8.6 |
redhat | enterprise_linux_eus | 9.0 |
redhat | enterprise_linux_for_power_little_endian | 8.0 |
redhat | enterprise_linux_for_power_little_endian | 9.0 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.2 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.4 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.6 |
redhat | enterprise_linux_for_power_little_endian_eus | 9.0 |
redhat | enterprise_linux_server_aus | 8.2 |
redhat | enterprise_linux_server_aus | 8.4 |
redhat | enterprise_linux_server_aus | 8.6 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.1 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.2 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.4 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.6 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 9.0 |
redhat | enterprise_linux_server_tus | 8.2 |
redhat | enterprise_linux_server_tus | 8.4 |
redhat | enterprise_linux_server_tus | 8.6 |
redhat | openshift_container_platform | 4.6 |
redhat | openshift_container_platform | 4.9 |
redhat | openshift_container_platform | 4.10 |
redhat | codeready_linux_builder | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
grub2 |
| ||||||||||||||||||||
grub2-signed |
| ||||||||||||||||||||
grub2-unsigned |
|
Common Weakness Enumeration
References