CVE-2023-4692 @ Library
Status
accepted_risk
Priority
3.75
Match score
4.0
Risk
RCE
MemCorrupt
CVSS
7.5 HIGH
Reason
cpe: grub2; pkgs: grub2-common; version: in-range: grub2-common-2.02~beta3-5+deb9u2; risk:rce
Created
2026-08-03T20:10:52Z
Updated
2026-08-22T10:17:49Z
Closed
2026-08-03T20:25:59Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| grub2-common-2.02~beta3-5+deb9u2 | |
| grub2 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: grub2-common · grub2
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
Debian GNU/Linux 9 (stretch)
(9)
· debian
Arch
x86_64
kernel_release
uname -r → 4.9.0-19-amd64kernel_version
uname -v → #1 SMP Debian 4.9.320-2 (2022-06-30)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | fixed | 9.0 | 2026-08-22T10:17:49Z | Open |
| mufasa | fixed | 9.0 | 2026-08-22T10:17:49Z | Open |
| Archive | accepted_risk | 2.62 | 2026-08-22T10:17:49Z | Open |
| Janus | accepted_risk | 2.62 | 2026-08-22T10:17:49Z | Open |
| Saiph | accepted_risk | 2.62 | 2026-08-22T10:17:49Z | Open |
Description
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Determination
Issue: Out-of-bounds write (heap overflow) in GRUB2’s NTFS filesystem driver. Impact: An attacker who can present a specially crafted NTFS filesystem image to GRUB can corrupt heap metadata. In some cases this can lead to arbitrary code execution in the boot environment and Secure Boot bypass. Attack requirements: Local access to control the boot media (e.g. USB, external drive, or in some network boot scenarios). Risk : Extremely low
Update status
Add note only
Mitigation log
2026-08-03T20:24:56Z — affects
Issue: Out-of-bounds write (heap overflow) in GRUB2’s NTFS filesystem driver.
Impact: An attacker who can present a specially crafted NTFS filesystem image to GRUB can corrupt heap metadata. In some cases this can lead to arbitrary code execution in the boot environment and Secure Boot bypass.
Attack requirements: Local access to control the boot media (e.g. USB, external drive, or in some network boot scenarios).
2026-08-03T20:25:25Z
Requires Physical Access to machine and NTFS boot media.
2026-08-03T20:25:59Z — accepted_risk
Risk : Extremely low
References
- https://access.redhat.com/errata/RHSA-2024:2456
- https://access.redhat.com/errata/RHSA-2024:3184
- https://access.redhat.com/security/cve/CVE-2023-4692
- https://bugzilla.redhat.com/show_bug.cgi?id=2236613
- https://dfir.ru/2023/10/03/cve-2023-4692-cve-2023-4693-vulnerabilities-in-the-grub-boot-manager/
- https://lists.gnu.org/archive/html/grub-devel/2023-10/msg00028.html
- https://seclists.org/oss-sec/2023/q4/37
- https://access.redhat.com/errata/RHSA-2024:2456
- https://access.redhat.com/errata/RHSA-2024:3184
- https://access.redhat.com/security/cve/CVE-2023-4692
- https://bugzilla.redhat.com/show_bug.cgi?id=2236613
- https://dfir.ru/2023/10/03/cve-2023-4692-cve-2023-4693-vulnerabilities-in-the-grub-boot-manager/
- https://lists.debian.org/debian-lts-announce/2023/10/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUU42E7CPYLATXOYVYNW6YTXXULAOV6L/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIRJ5UZRXX2KLR4IKBJEQUNGOCXMMDLY/
NVD: CVE-2023-4692