CVE-2022-28733

high
Published 2022-06-16 · Modified 2022-06-16
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

RHSA-2022:5095: grub2, mokutil, shim, and shim-unsigned-x64 security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description grub2: Integer underflow in grub_net_recv_ip4_packets CVSS v3: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7grub2-1:2.02-0.87.el7_9.11RHSA-2022:89002022-12-08T00:00:00Z Red Hat Enterprise Linux 8grub2-1:2.02-123.el8_6.8RHSA-2022:50952022-06-16T00:00:00Z Red Hat Enterprise Linux 8.1 Update Services…

Description

grub2: Integer underflow in grub_net_recv_ip4_packets

CVSS v3: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7grub2-1:2.02-0.87.el7_9.11RHSA-2022:89002022-12-08T00:00:00Z
Red Hat Enterprise Linux 8grub2-1:2.02-123.el8_6.8RHSA-2022:50952022-06-16T00:00:00Z
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionsgrub2-1:2.02-87.el8_1.10RHSA-2022:50982022-06-16T00:00:00Z
Red Hat Enterprise Linux 8.2 Extended Update Supportgrub2-1:2.02-87.el8_2.10RHSA-2022:51002022-06-16T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportgrub2-1:2.02-99.el8_4.9RHSA-2022:50962022-06-16T00:00:00Z
Red Hat Enterprise Linux 9grub2-1:2.06-27.el9_0.7RHSA-2022:50992022-06-16T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-host-0:4.5.1-202207170705_8.6RHSA-2022:56782022-07-21T00:00:00Z

Apply commands

bash fix
Apply RHSA-2022:8900 for Red Hat Enterprise Linux 7
yum update -y grub2
# or:
dnf upgrade -y grub2

OS impact

OSVersionStatusFixed in
arch archaffected
redhat rhel9fixed
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed2.06-3
debian debianbullseyefixed2.06-3~deb11u1
debian debianforkyfixed2.06-3
debian debiansidfixed2.06-3
debian debiantrixiefixed2.06-3
rockylinux rocky9fixed
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.