#VU64059 Out-of-bounds write in grub - CVE-2021-3696
Published: June 8, 2022 / Updated: July 20, 2022
grub
GNU
Description
The vulnerability allows a local privileged user to bypass implemented security restrictions.
The vulnerability exists due to a boundary error when handling Huffman tables in the PNG reader. A local privileged user can pass specially crafted PNG image to the application, trigger an out-of-bounds write error and potentially bypass secure boot protection mechanism.