Bug 1217067 (CVE-2023-4949) - VUL-0: CVE-2023-4949: grub: memory corruption in XFS file system implementation
Summary: VUL-0: CVE-2023-4949: grub: memory corruption in XFS file system implementation
Status: RESOLVED FIXED
Alias: CVE-2023-4949
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: package coldpool
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/384532/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-4949:8.1:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-13 08:41 UTC by SMASH SMASH
Modified: 2024-03-19 05:23 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-11-13 08:41:18 UTC
An attacker with local access to a system (either through a disk or external
drive) can present a modified XFS partition to grub-legacy in such a way to
exploit a memory corruption in grub’s XFS file system implementation.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4949
Comment 1 Carlos López 2023-11-13 08:42:58 UTC
I assume "grub-legacy" means grub instead of grub2. This is related to CVE-2023-34325 (bsc#1215747).
Comment 2 Carlos López 2023-11-13 08:43:47 UTC
(In reply to Carlos López from comment #1)
> I assume "grub-legacy" means grub instead of grub2.

grub2 maintainers, can you confirm?
Comment 3 Michael Chang 2023-11-14 01:25:02 UTC
(In reply to Carlos López from comment #2)
> (In reply to Carlos López from comment #1)
> > I assume "grub-legacy" means grub instead of grub2.
> 
> grub2 maintainers, can you confirm?

Yes. To avoid confusion, grub-legacy is often used to refer to old grub which's development ended in 0.97.  Also I didn't see discussion about XFS vulnerability recently in "grub2" upstream.
Comment 4 Carlos López 2023-11-15 13:54:35 UTC
(In reply to Michael Chang from comment #3)
> (In reply to Carlos López from comment #2)
> > (In reply to Carlos López from comment #1)
> > > I assume "grub-legacy" means grub instead of grub2.
> > 
> > grub2 maintainers, can you confirm?
> 
> Yes. To avoid confusion, grub-legacy is often used to refer to old grub
> which's development ended in 0.97.  Also I didn't see discussion about XFS
> vulnerability recently in "grub2" upstream.

Thanks, closing this since we do not ship legacy grub.
Comment 5 Carlos López 2023-11-15 14:26:44 UTC
(In reply to Carlos López from comment #4)
> Thanks, closing this since we do not ship legacy grub.

(Actually it is technically under L3 support)