<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:24:31.279308+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:0049</id>
    <title>ALSA-2023:0049 — Moderate: grub2 security update</title>
    <updated>2026-10-02T16:24:31.307075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 8 more</p>
<p>The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.</p>
<p>Security Fix(es):</p>
<p>* grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass (CVE-2022-2601)
* grub2: Heap based out-of-bounds write when redering certain unicode sequences (CVE-2022-3775)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:0049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06819</id>
    <title>bdu:2022-06819</title>
    <updated>2026-10-02T16:24:31.307157+00:00</updated>
    <content>bdu:2022-06819</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-2601</id>
    <title>Withdrawn: BELL-CVE-2022-2601 — CVE-2022-2601 does not affect BellSoft software</title>
    <updated>2026-10-02T16:24:31.307174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-2601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0240</id>
    <title>certfr-2023-avi-0240 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-02T16:24:31.307189+00:00</updated>
    <content>certfr-2023-avi-0240</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/esea-2023:0073</id>
    <title>ESEA-2023:0073 — Enhancement update for</title>
    <updated>2026-10-02T16:24:31.307203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Enhancement update for</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/esea-2023:0073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321985</id>
    <title>EUVD-2026-321985</title>
    <updated>2026-10-02T16:24:31.307252+00:00</updated>
    <content>EUVD-2026-321985</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321985"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2601</id>
    <title>fkie_cve-2022-2601</title>
    <updated>2026-10-02T16:24:31.307273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c8f6-x9xm-x27g</id>
    <title>GHSA-c8f6-x9xm-x27g</title>
    <updated>2026-10-02T16:24:31.307307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c8f6-x9xm-x27g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2601</id>
    <title>gsd-2022-2601</title>
    <updated>2026-10-02T16:24:31.307323+00:00</updated>
    <content>gsd-2022-2601</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-2118</id>
    <title>OESA-2022-2118 — grub2 security update</title>
    <updated>2026-10-02T16:24:31.307333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: grub2, openEuler:20.03-LTS-SP3: grub2, openEuler:22.03-LTS: grub2</p>
<p>GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).

Security Fix(es):

A flaw was found where a maliciously crafted pf2 font could lead to an out-of-bounds write in grub2. A successful attack can lead to memory corruption and secure boot circumvention.(CVE-2022-2601)

A flaw was found in the grub2 font code. When rendering certain unicode sequences, it fails to properly validate the font width and height. These values are further used to access the font buffer, causing possible out-of-bounds writes. A malicious actor may craft a font capable of triggering this issue, allowing modifications in unauthorized memory segments, causing data integrity problems or leading to denial of service.(CVE-2022-3775)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-2118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:8494</id>
    <title>RHSA-2022:8494 — Red Hat Security Advisory: grub2 security update</title>
    <updated>2026-10-02T16:24:31.307362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass grub2: Heap based out-of-bounds write when redering certain unicode sequences</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:8494"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:4140-1</id>
    <title>SUSE-SU-2022:4140-1 — Security update for grub2</title>
    <updated>2026-10-02T16:24:31.307381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:4140-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2601</id>
    <title>UBUNTU-CVE-2022-2601</title>
    <updated>2026-10-02T16:24:31.307395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned</p>
<p>A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2058</id>
    <title>WID-SEC-W-2022-2058 — Grub2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:24:31.307423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Grub ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2058"/>
  </entry>
</feed>
