Vulnerability record · CVE-2021-3696 · published 6 July 2022
CVE-2021-3696: Gnu grub2 out-of-bounds write vulnerability
Gnu · Grub2
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
Description
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1991686 | Issue TrackingThird Party Advisory |
| https://security.gentoo.org/glsa/202209-12 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220930-0001/ | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1991686 | Issue TrackingThird Party Advisory |
| https://security.gentoo.org/glsa/202209-12 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220930-0001/ | Third Party Advisory |
Track CVE-2021-3696 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3696), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.