← Back

Grub

grub

Vendor: Gnu • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Gnu
Xen
2Grub
Xen
Jun 17, 2026
Nov 10, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementatio...Show more
An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation. Show less
1Gnu
1Grub
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.