PT-2023-4426 · Unknown · Efibootguard

Onionpsy

·

Published

2023-08-14

·

Updated

2023-08-22

·

CVE-2023-39950

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions efibootguard versions prior to v0.15
Description The issue exists due to insufficient validation and sanitization of input from untrustworthy bootloader environment files, which can cause crashes and potentially allow code injections into bg setenv or programs using libebgenv. This is triggered when the affected components try to modify a manipulated environment, specifically its user variables. Furthermore, bg printenv may crash over invalid read accesses or report invalid results.
Recommendations To resolve the issue, update the efibootguard library and tools to version v0.15 or later. Additionally, update programs that are statically linked against it. As a temporary workaround, consider avoiding accesses to user variables, specifically modifications to them, until the update is applied. Note that an update of the bootloader EFI executable is not required.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04771
CVE-2023-39950
GHSA-J6PP-7G99-24M7

Affected Products

Efibootguard