Unrated severityNVD Advisory· Published Oct 25, 2023· Updated Nov 7, 2025
Grub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code execution
CVE-2023-4692
Description
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- access.redhat.com/errata/RHSA-2024:2456mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2024:3184mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2023-4692mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- dfir.ru/2023/10/03/cve-2023-4692-cve-2023-4693-vulnerabilities-in-the-grub-boot-manager/mitre
- lists.gnu.org/archive/html/grub-devel/2023-10/msg00028.htmlmitre
- seclists.org/oss-sec/2023/q4/37mitre
News mentions
0No linked articles in our index yet.