Assessment
Why it matters
EPSS is 0.5%; technical severity is CVSS 7.8.
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Who should care
- Teams operating Grub2, Enterprise Linux
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Grub2, Enterprise Linux is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Red Hat Security advisory RHSA-2024:2456
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
- Red Hat Security advisory RHSA-2024:2456Red Hat · Vendor sourceVerification pending ↗
- Red Hat Security advisory RHSA-2024:3184Red Hat · Vendor sourceVerification pending ↗
- Red Hat Security advisory CVE-2023-4692Red Hat · Vendor sourceVerification pending ↗
- Debian Security advisory Msg00007Debian · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-122
- Affected versions
- GNU Grub2 (End Excluding 2.12); Redhat Enterprise Linux (Version 8.0 | Version 9.0)
- Fixed versions
- GNU Grub2 (Fixed from 2.12)
- Published
- 25 October 2023
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Latest EPSS score: 0.5%
- Signal calculated at 12
External references
- Red Hat Third-party advisory Show Bug.cgi
- Exploit information from dfir.ru
- Lists Gnu Technical reference Msg00028
- Seclists Third-party advisory
- Lists Fedoraproject Technical reference FUU42E7CPYLATXOYVYNW6YTXXULAOV6L
- Lists Fedoraproject Technical reference OIRJ5UZRXX2KLR4IKBJEQUNGOCXMMDLY
- Lists Fedoraproject Technical reference PERFILCHFEUGG3OAMC6W55P6DDIBZK4Q
- Security Gentoo Technical reference 202311 14
- Security Netapp Technical reference Ntap 20231208 0002