Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34791.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-34791
Upstream
Published
2023-07-20T01:15:10Z
Modified
2026-04-01T05:11:41.927129Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2022-28736 affecting package grub2 for versions less than 2.06-14
Details

There's a use-after-free vulnerability in grubcmdchainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free vulnerability is triggered. If an attacker can control the GRUB2's memory allocation pattern sensitive data may be exposed and arbitrary code execution can be achieved.

References

Affected packages

Azure Linux:3 / grub2

Package

Name
grub2
Purl
pkg:rpm/azure-linux/grub2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.06-14

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34791.json"