#VU69394 Out-of-bounds write in grub - CVE-2022-2601
Published: November 16, 2022 / Updated: October 5, 2023
grub
GNU
Description
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to a boundary error within the grub_font_construct_glyph() function when handling pf2 font. An attacker with physical access to the affected system can trigger an out-of-bounds write and bypass secure boot restrictions.