#VU51198 Out-of-bounds write in grub - CVE-2021-20233
Published: March 3, 2021 / Updated: December 17, 2024
grub
GNU
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the setparam_prefix() function in menu rendering code. A local privileged user can run a specially crafted program to trigger out-of-bounds write and escalate privileges on the system.