{
  "threat_severity" : "Moderate",
  "public_date" : "2022-06-07T17:00:00Z",
  "bugzilla" : {
    "description" : "grub2: Out-of-bound write when handling split HTTP headers",
    "id" : "2090463",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2090463"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-787",
  "details" : [ "Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.", "A flaw was found in grub2 when handling split HTTP headers. While processing a split HTTP header, grub2 wrongly advances its control pointer to the internal buffer by one position, which can lead to an out-of-bounds write. This flaw allows an attacker to leverage this issue by crafting a malicious set of HTTP packages making grub2 corrupt its internal memory metadata structure. This leads to data integrity and confidentiality issues or forces grub to crash, resulting in a denial of service attack." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2022-06-16T00:00:00Z",
    "advisory" : "RHSA-2022:5095",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "grub2-1:2.02-123.el8_6.8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions",
    "release_date" : "2022-06-16T00:00:00Z",
    "advisory" : "RHSA-2022:5098",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.1",
    "package" : "grub2-1:2.02-87.el8_1.10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Extended Update Support",
    "release_date" : "2022-06-16T00:00:00Z",
    "advisory" : "RHSA-2022:5100",
    "cpe" : "cpe:/o:redhat:rhel_eus:8.2",
    "package" : "grub2-1:2.02-87.el8_2.10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support",
    "release_date" : "2022-06-16T00:00:00Z",
    "advisory" : "RHSA-2022:5096",
    "cpe" : "cpe:/o:redhat:rhel_eus:8.4",
    "package" : "grub2-1:2.02-99.el8_4.9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2022-06-16T00:00:00Z",
    "advisory" : "RHSA-2022:5099",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "grub2-1:2.06-27.el9_0.7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "grub2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-28734\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-28734" ],
  "name" : "CVE-2022-28734",
  "csaw" : false
}