MEDIUM · 4.5

CVE-2021-3695

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and...

Vulnerability Description

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

CVSS Score

4.5

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
GnuGrub2>= 2.00, < 2.12
FedoraprojectFedora36
RedhatDeveloper Tools1.0
RedhatOpenshift3.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.2
RedhatEnterprise Linux For Power Little Endian8.0
RedhatEnterprise Linux For Power Little Endian Eus8.2
RedhatEnterprise Linux Server Aus8.2
RedhatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutions8.1
RedhatEnterprise Linux Server Tus8.2
RedhatOpenshift Container Platform4.6
RedhatCodeready Linux Builder-
NetappOntap Select Deploy Administration Utility-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3695?

CVE-2021-3695 is a vulnerability with a CVSS score of 4.5 (MEDIUM). A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and...

How severe is CVE-2021-3695?

CVE-2021-3695 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3695?

Check the references section above for vendor advisories and patch information. Affected products include: Gnu Grub2, Fedoraproject Fedora, Redhat Developer Tools, Redhat Openshift, Redhat Enterprise Linux.