CVE Tracker

CVE-2023-4692 @ morris

Status
fixed
Priority
9.0
Match score
4.0
Risk
RCE MemCorrupt
CVSS
7.5 HIGH
Reason
cpe: grub2; pkgs: grub2, grub2-common, grub2-efi-x64, grub2-pc, grub2-pc-modules, grub2-tools; version: in-range: grub2-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5, grub2-common-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5, grub2-efi-x64-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5, grub2-pc-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5, grub2-pc-modules-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5, grub2-tools-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5; risk:rce
Created
2026-08-02T16:53:21Z
Updated
2026-08-22T10:17:49Z
Closed
2026-08-02T19:25:02Z

Package interrogation (copy)

Run on the host — click to copy a command. RPM

PackageCommands
grub2-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5
grub2-common-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5
grub2-efi-x64-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5
grub2-pc-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5
grub2-pc-modules-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5
grub2-tools-2.02-0.87.el7_9.14.cloudlinux.1.tuxcare.els5

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Suggestions: grub2 · grub2-common · grub2-efi-x64 · grub2-pc · grub2-pc-modules · grub2-tools

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
CloudLinux release 7.9 (Boris Yegorov) (7.9) · cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64
kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
mufasa fixed 9.0 2026-08-22T10:17:49Z Open
Library accepted_risk 3.75 2026-08-22T10:17:49Z Open
Archive accepted_risk 2.62 2026-08-22T10:17:49Z Open
Janus accepted_risk 2.62 2026-08-22T10:17:49Z Open
Saiph accepted_risk 2.62 2026-08-22T10:17:49Z Open

Description

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

Determination

No, you are not vulnerable.

TuxCare released the fix for this CVE in the els5 rebuild of exactly this version:

Advisory: CLSA-2026:1779219098
Fixed packages: grub2-2.02-0.87.el7_9.14.tuxcare.els5 (and the corresponding CloudLinux-branded packages)

Installed packages match the fixed version.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-02T19:25:02Z — fixed
No, you are not vulnerable. TuxCare released the fix for this CVE in the els5 rebuild of exactly this version: Advisory: CLSA-2026:1779219098 Fixed packages: grub2-2.02-0.87.el7_9.14.tuxcare.els5 (and the corresponding CloudLinux-branded packages) Installed packages match the fixed version.

References

NVD: CVE-2023-4692