<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:26:31 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:0049 — Moderate: grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0049</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 8 more&lt;/p&gt;
&lt;p&gt;The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass (CVE-2022-2601)
* grub2: Heap based out-of-bounds write when redering certain unicode sequences (CVE-2022-3775)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 8 more&lt;/p&gt;
&lt;p&gt;The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass (CVE-2022-2601)
* grub2: Heap based out-of-bounds write when redering certain unicode sequences (CVE-2022-3775)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0049</guid>
    </item>
    <item>
      <title>bdu:2022-06820</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06820</link>
      <description>bdu:2022-06820</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06820</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-3775 — CVE-2022-3775 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-3775</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-3775</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0726 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux d'Ubuntu&lt;/span&gt;. Certaines d'e…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726</link>
      <description>certfr-2023-avi-0726</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726</guid>
    </item>
    <item>
      <title>ESEA-2023:0073 — Enhancement update for</title>
      <link>https://cve.radiocsirt.org/vuln/esea-2023:0073</link>
      <description>&lt;p&gt;Enhancement update for&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Enhancement update for&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/esea-2023:0073</guid>
    </item>
    <item>
      <title>EUVD-2026-321971</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321971</link>
      <description>EUVD-2026-321971</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321971</guid>
    </item>
    <item>
      <title>fkie_cve-2022-3775</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3775</link>
      <description>&lt;p&gt;When rendering certain unicode sequences, grub2&amp;#39;s font code doesn&amp;#39;t proper validate if the informed glyph&amp;#39;s width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2&amp;#39;s heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When rendering certain unicode sequences, grub2&amp;#39;s font code doesn&amp;#39;t proper validate if the informed glyph&amp;#39;s width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2&amp;#39;s heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-3775</guid>
    </item>
    <item>
      <title>GHSA-8h84-vmjf-pcmj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8h84-vmjf-pcmj</link>
      <description>&lt;p&gt;When rendering certain unicode sequences, grub2&amp;#39;s font code doesn&amp;#39;t proper validate if the informed glyph&amp;#39;s width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2&amp;#39;s heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When rendering certain unicode sequences, grub2&amp;#39;s font code doesn&amp;#39;t proper validate if the informed glyph&amp;#39;s width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2&amp;#39;s heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8h84-vmjf-pcmj</guid>
    </item>
    <item>
      <title>gsd-2022-3775</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-3775</link>
      <description>gsd-2022-3775</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-3775</guid>
    </item>
    <item>
      <title>OESA-2022-2118 — grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2118</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: grub2, openEuler:20.03-LTS-SP3: grub2, openEuler:22.03-LTS: grub2&lt;/p&gt;
&lt;p&gt;GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found where a maliciously crafted pf2 font could lead to an out-of-bounds write in grub2. A successful attack can lead to memory corruption and secure boot circumvention.(CVE-2022-2601)&#13;
&#13;
A flaw was found in the grub2 font code. When rendering certain unicode sequences, it fails to properly validate the font width and height. These values are further used to access the font buffer, causing possible out-of-bounds writes. A malicious actor may craft a font capable of triggering this issue, allowing modifications in unauthorized memory segments, causing data integrity problems or leading to denial of service.(CVE-2022-3775)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: grub2, openEuler:20.03-LTS-SP3: grub2, openEuler:22.03-LTS: grub2&lt;/p&gt;
&lt;p&gt;GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found where a maliciously crafted pf2 font could lead to an out-of-bounds write in grub2. A successful attack can lead to memory corruption and secure boot circumvention.(CVE-2022-2601)&#13;
&#13;
A flaw was found in the grub2 font code. When rendering certain unicode sequences, it fails to properly validate the font width and height. These values are further used to access the font buffer, causing possible out-of-bounds writes. A malicious actor may craft a font capable of triggering this issue, allowing modifications in unauthorized memory segments, causing data integrity problems or leading to denial of service.(CVE-2022-3775)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2118</guid>
    </item>
    <item>
      <title>RHSA-2022:8494 — Red Hat Security Advisory: grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:8494</link>
      <description>&lt;p&gt;grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass grub2: Heap based out-of-bounds write when redering certain unicode sequences&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grub2: Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass grub2: Heap based out-of-bounds write when redering certain unicode sequences&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:8494</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4140-1 — Security update for grub2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4140-1</link>
      <description>&lt;p&gt;Security update for grub2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grub2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4140-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-3775</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3775</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned&lt;/p&gt;
&lt;p&gt;When rendering certain unicode sequences, grub2&amp;#39;s font code doesn&amp;#39;t proper validate if the informed glyph&amp;#39;s width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2&amp;#39;s heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned&lt;/p&gt;
&lt;p&gt;When rendering certain unicode sequences, grub2&amp;#39;s font code doesn&amp;#39;t proper validate if the informed glyph&amp;#39;s width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2&amp;#39;s heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3775</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2058 — Grub2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2058</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Grub ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Grub ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2058</guid>
    </item>
  </channel>
</rss>
