PT-2023-5885 · Grub2+10 · Grub2+10

Maxim Suhanov

·

Published

2023-10-03

·

Updated

2025-06-16

·

CVE-2023-4693

CVSS v3.1

5.3

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grub2 (affected versions not specified)
Description The issue is related to an out-of-bounds read flaw in Grub2's NTFS filesystem driver. This flaw may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations, potentially leading to the leakage of sensitive data cached in memory or EFI variable values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2024:2456
ALSA-2024:3184
ALT-PU-2024-11222
ALT-PU-2024-1455
ALT-PU-2024-1457
ALT-PU-2024-1607
ALT-PU-2024-1609
ALT-PU-2024-1869
ALT-PU-2024-4050
AZL-31685
AZL-34794
BDU:2023-06578
CESA-2024_3184
CVE-2023-4693
DLA-3605-1
DSA-5519-1
INFSA-2024_2456
INFSA-2024_3184
MGASA-2024-0095
OESA-2023-1720
OPENSUSE-SU-2024:13328-1
RHSA-2024:2456
RHSA-2024:3184
RHSA-2024_2456
RHSA-2024_3184
RLSA-2024:3184
ROSA-SA-2025-2606
SUSE-SU-2023:4085-1
SUSE-SU-2023:4130-1
SUSE-SU-2023:4140-1
SUSE-SU-2023:4141-1
SUSE-SU-2025:01961-1
USN-6410-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Grub2
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu