<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:52:03.796694+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:5095</id>
    <title>ALSA-2022:5095 — Important: grub2, mokutil, shim, and shim-unsigned-x64 security update</title>
    <updated>2026-10-02T23:52:03.815512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 11 more</p>
<p>The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.
The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.
Security Fix(es):
* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)
* grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695)
* grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696)
* grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697)
* grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734)
* grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735)
* grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736)
* shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:5095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01200</id>
    <title>bdu:2024-01200</title>
    <updated>2026-10-02T23:52:03.815703+00:00</updated>
    <content>bdu:2024-01200</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01200"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-28735</id>
    <title>Withdrawn: BELL-CVE-2022-28735 — CVE-2022-28735 does not affect BellSoft software</title>
    <updated>2026-10-02T23:52:03.815736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-28735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726</id>
    <title>certfr-2023-avi-0726 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux d'Ubuntu&lt;/span&gt;. Certaines d'e…</title>
    <updated>2026-10-02T23:52:03.815770+00:00</updated>
    <content>certfr-2023-avi-0726</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216024</id>
    <title>EUVD-2026-216024</title>
    <updated>2026-10-02T23:52:03.815814+00:00</updated>
    <content>EUVD-2026-216024</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-28735</id>
    <title>fkie_cve-2022-28735</title>
    <updated>2026-10-02T23:52:03.815835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-28735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w8wh-9mrg-3ff5</id>
    <title>GHSA-w8wh-9mrg-3ff5</title>
    <updated>2026-10-02T23:52:03.815874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w8wh-9mrg-3ff5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-28735</id>
    <title>gsd-2022-28735</title>
    <updated>2026-10-02T23:52:03.815901+00:00</updated>
    <content>gsd-2022-28735</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-28735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-28735</id>
    <title>msrc_CVE-2022-28735 — The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such…</title>
    <updated>2026-10-02T23:52:03.815919+00:00</updated>
    <content>msrc_CVE-2022-28735</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-28735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1734</id>
    <title>OESA-2022-1734 — grub2 security update</title>
    <updated>2026-10-02T23:52:03.815949+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: grub2, openEuler:20.03-LTS-SP3: grub2, openEuler:22.03-LTS: grub2</p>
<p>GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.

Security Fix(es):

A flaw was found in grub2 when handling split HTTP headers. While processing a split HTTP header, grub2 wrongly advances its control pointer to the internal buffer by one position, which can lead to an out-of-bounds write. This flaw allows an attacker to leverage this issue by crafting a malicious set of HTTP packages making grub2 corrupt its internal memory metadata structure. This leads to data integrity and confidentiality issues or forces grub to crash, resulting in a denial of service attack.(CVE-2022-28734)

A use-after-free vulnerability was found on grub2's chainloader command. This flaw allows an attacker to gain access to restricted data or cause arbitrary code execution if they can establish control from grub's memory allocation pattern.(CVE-2022-28736)

A flaw was found in grub2 when handling JPEG images. This flaw allows an attacker to craft a malicious JPEG image, which leads to an underflow on a grub2's internal pointer, leading to a heap-based out-of-bounds write. Secure-boot mechanisms circumvention and arbitrary code execution may also be achievable.(CVE-2021-3697)

A flaw was found in grub2 when handling a PNG image header. When decoding the data contained in the Huffman table at the PNG file header, an out-of-bounds write may happen on grub's heap.(CVE-2021-3696)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1734"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12137-1</id>
    <title>openSUSE-SU-2024:12137-1 — grub2-2.06-25.1 on GA media</title>
    <updated>2026-10-02T23:52:03.816038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2-2.06-25.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12137-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5095</id>
    <title>RHSA-2022:5095 — Red Hat Security Advisory: grub2, mokutil, shim, and shim-unsigned-x64 security update</title>
    <updated>2026-10-02T23:52:03.816069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling grub2: Crafted JPEG image can lead to buffer underflow write in the heap grub2: Integer underflow in grub_net_recv_ip4_packets grub2: Out-of-bound write when handling split HTTP headers grub2: shim_lock verifier allows non-kernel files to be loaded grub2: use-after-free in grub_cmd_chainloader() shim: Buffer overflow when loading crafted EFI images</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2064-1</id>
    <title>SUSE-SU-2022:2064-1 — Security update for grub2</title>
    <updated>2026-10-02T23:52:03.816118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2064-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-28735</id>
    <title>UBUNTU-CVE-2022-28735</title>
    <updated>2026-10-02T23:52:03.816146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned</p>
<p>The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-28735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0181</id>
    <title>WID-SEC-W-2022-0181 — Grub2: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T23:52:03.816203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Oracle Linux ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0181"/>
  </entry>
</feed>
