Exploit maturity not defined.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for RHEL:7
grub2-tools-minimal
.
Note: Versions mentioned in the description apply only to the upstream grub2-tools-minimal
package and not the grub2-tools-minimal
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issues and eventually allowing an attacker to circumvent secure boot protections.