CVE-2023-4949

Publication date 10 November 2023

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.7 · Medium

Score breakdown

Description

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

Read the notes from the security team

Status

Package Ubuntu Release Status
grub 24.04 LTS noble Not in release
23.10 mantic Not in release
23.04 lunar Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Not in release
18.04 LTS bionic Ignored end of standard support
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Notes


eslerm

does not impact secure boot

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.7 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities