CVE-2023-4693

MEDIUM

GNU Grub2 < 2.12 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 1.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (3)
gnu/grub2 < 2.12
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
Published Oct 25, 2023
Tracked Since Feb 18, 2026