Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34788.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-34788
Upstream
Published
2023-07-20T01:15:10Z
Modified
2026-04-01T05:11:41.691883Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2022-28733 affecting package grub2 for versions less than 2.06-14
Details

Integer underflow in grubnetrecvip4packets; A malicious crafted IP packet can lead to an integer underflow in grubnetrecvip4packets() function on rsm->totallen value. Under certain circumstances the totallen value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

References

Affected packages

Azure Linux:3 / grub2

Package

Name
grub2
Purl
pkg:rpm/azure-linux/grub2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.06-14

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34788.json"