CVE-2022-28734
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- gnu/grub2 · netapp/active iq unified manager
- Source
- security@ubuntu.com
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28734Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230825-0002/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/06/07/5Mailing List, Third Party Advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28734Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230825-0002/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/06/07/5Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.