CVE-2021-3697 is a heap underflow vulnerability in grub2 versions prior to 2.12, affecting GNU and Red Hat products. A specially crafted JPEG image can cause the JPEG reader to underflow its data pointer, allowing an attacker to write user-controlled data to the heap. This high-severity flaw (CVSS 7.0) requires an attacker to manipulate the heap layout and craft a malicious image, potentially leading to data corruption, code execution, or secure boot circumvention. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.00, < 2.12CPE matchmatch criteria | cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift:3.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-3697
Jun 11, 2024A crafted JPEG image may lead the JPEG reader to underflow its data pointer allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
Jul 12, 2022grub2: Crafted JPEG image can lead to buffer underflow write in the heap
Jun 7, 2022