#VU64067 Out-of-bounds write in grub - CVE-2022-28737
Published: June 8, 2022 / Updated: July 20, 2022
grub
GNU
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to a boundary error in the handle_image() function when shim tries to load and execute crafted EFI executables. A local privileged user can trigger an out-of-bounds write error and bypass secure boot protection mechanism.