CVE-2023-4693Medium· 5.3▾ SunlitAn out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allo…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk.
grub2 < 2.12enterprise_linux = 8.0enterprise_linux = 9.0Upgrade past the affected range:
grub2 2.12Connected by shared product, vendor, weakness, or advisory.
CVE-2023-4692High· 7.5An out-of-bounds write flaw was found in grub2's NTFS filesystem driver
CVE-2022-29458High· 7.1ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
CVE-2026-41992High· 7.5GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution
CVE-2026-4647Medium· 6.1A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables
CVE-2026-3442Medium· 6.1A flaw was found in GNU Binutils
CVE-2026-3441Medium· 6.1A flaw was found in GNU Binutils