Description
Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33172 | Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer. |
Ubuntu USN |
USN-6355-1 | GRUB2 vulnerabilities |
References
History
Thu, 24 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-02-13T16:32:35.678Z
Reserved: 2022-04-05T21:59:08.759Z
Link: CVE-2022-28733
Updated: 2024-08-03T06:03:52.571Z
Status : Modified
Published: 2023-07-20T01:15:10.140
Modified: 2024-11-21T06:57:49.677
Link: CVE-2022-28733
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN