<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:43:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:5095 — Important: grub2, mokutil, shim, and shim-unsigned-x64 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:5095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 11 more&lt;/p&gt;
&lt;p&gt;The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.
The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.
Security Fix(es):
* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)
* grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695)
* grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696)
* grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697)
* grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734)
* grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735)
* grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736)
* shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 11 more&lt;/p&gt;
&lt;p&gt;The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.
The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.
Security Fix(es):
* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)
* grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695)
* grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696)
* grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697)
* grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734)
* grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735)
* grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736)
* shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:5095</guid>
    </item>
    <item>
      <title>bdu:2022-06896</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06896</link>
      <description>bdu:2022-06896</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06896</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3696 — CVE-2021-3696 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3696</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3696</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0726 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux d'Ubuntu&lt;/span&gt;. Certaines d'e…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726</link>
      <description>certfr-2023-avi-0726</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726</guid>
    </item>
    <item>
      <title>EUVD-2026-21032</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21032</link>
      <description>EUVD-2026-21032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21032</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3696</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3696</link>
      <description>&lt;p&gt;A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it&amp;#39;s very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it&amp;#39;s very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3696</guid>
    </item>
    <item>
      <title>GHSA-mv5h-82v3-mq2x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mv5h-82v3-mq2x</link>
      <description>&lt;p&gt;A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it&amp;#39;s very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it&amp;#39;s very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mv5h-82v3-mq2x</guid>
    </item>
    <item>
      <title>gsd-2021-3696</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3696</link>
      <description>gsd-2021-3696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3696</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3696 — A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data co…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3696</link>
      <description>msrc_CVE-2021-3696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3696</guid>
    </item>
    <item>
      <title>OESA-2022-1734 — grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1734</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: grub2, openEuler:20.03-LTS-SP3: grub2, openEuler:22.03-LTS: grub2&lt;/p&gt;
&lt;p&gt;GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in grub2 when handling split HTTP headers. While processing a split HTTP header, grub2 wrongly advances its control pointer to the internal buffer by one position, which can lead to an out-of-bounds write. This flaw allows an attacker to leverage this issue by crafting a malicious set of HTTP packages making grub2 corrupt its internal memory metadata structure. This leads to data integrity and confidentiality issues or forces grub to crash, resulting in a denial of service attack.(CVE-2022-28734)&#13;
&#13;
A use-after-free vulnerability was found on grub2&amp;#39;s chainloader command. This flaw allows an attacker to gain access to restricted data or cause arbitrary code execution if they can establish control from grub&amp;#39;s memory allocation pattern.(CVE-2022-28736)&#13;
&#13;
A flaw was found in grub2 when handling JPEG images. This flaw allows an attacker to craft a malicious JPEG image, which leads to an underflow on a grub2&amp;#39;s internal pointer, leading to a heap-based out-of-bounds write. Secure-boot mechanisms circumvention and arbitrary code execution may also be achievable.(CVE-2021-3697)&#13;
&#13;
A flaw was found in grub2 when handling a PNG image header. When decoding the data contained in the Huffman table at the PNG file header, an out-of-bounds write may happen on grub&amp;#39;s heap.(CVE-2021-3696)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: grub2, openEuler:20.03-LTS-SP3: grub2, openEuler:22.03-LTS: grub2&lt;/p&gt;
&lt;p&gt;GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in grub2 when handling split HTTP headers. While processing a split HTTP header, grub2 wrongly advances its control pointer to the internal buffer by one position, which can lead to an out-of-bounds write. This flaw allows an attacker to leverage this issue by crafting a malicious set of HTTP packages making grub2 corrupt its internal memory metadata structure. This leads to data integrity and confidentiality issues or forces grub to crash, resulting in a denial of service attack.(CVE-2022-28734)&#13;
&#13;
A use-after-free vulnerability was found on grub2&amp;#39;s chainloader command. This flaw allows an attacker to gain access to restricted data or cause arbitrary code execution if they can establish control from grub&amp;#39;s memory allocation pattern.(CVE-2022-28736)&#13;
&#13;
A flaw was found in grub2 when handling JPEG images. This flaw allows an attacker to craft a malicious JPEG image, which leads to an underflow on a grub2&amp;#39;s internal pointer, leading to a heap-based out-of-bounds write. Secure-boot mechanisms circumvention and arbitrary code execution may also be achievable.(CVE-2021-3697)&#13;
&#13;
A flaw was found in grub2 when handling a PNG image header. When decoding the data contained in the Huffman table at the PNG file header, an out-of-bounds write may happen on grub&amp;#39;s heap.(CVE-2021-3696)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1734</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12137-1 — grub2-2.06-25.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12137-1</link>
      <description>&lt;p&gt;grub2-2.06-25.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grub2-2.06-25.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12137-1</guid>
    </item>
    <item>
      <title>RHSA-2022:5095 — Red Hat Security Advisory: grub2, mokutil, shim, and shim-unsigned-x64 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:5095</link>
      <description>&lt;p&gt;grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling grub2: Crafted JPEG image can lead to buffer underflow write in the heap grub2: Integer underflow in grub_net_recv_ip4_packets grub2: Out-of-bound write when handling split HTTP headers grub2: shim_lock verifier allows non-kernel files to be loaded grub2: use-after-free in grub_cmd_chainloader() shim: Buffer overflow when loading crafted EFI images&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling grub2: Crafted JPEG image can lead to buffer underflow write in the heap grub2: Integer underflow in grub_net_recv_ip4_packets grub2: Out-of-bound write when handling split HTTP headers grub2: shim_lock verifier allows non-kernel files to be loaded grub2: use-after-free in grub_cmd_chainloader() shim: Buffer overflow when loading crafted EFI images&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:5095</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:2036-1 — Security update for grub2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:2036-1</link>
      <description>&lt;p&gt;Security update for grub2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grub2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:2036-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3696</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3696</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned&lt;/p&gt;
&lt;p&gt;A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it&amp;#39;s very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned&lt;/p&gt;
&lt;p&gt;A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it&amp;#39;s very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3696</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0181 — Grub2: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0181</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Oracle Linux ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Oracle Linux ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0181</guid>
    </item>
  </channel>
</rss>
