CVE-2022-2601HighCVSS 8.6

Redhat: CVE-2022-2601 grub2 - Buffer overflow in grub_font_construct_glyph() can lead to out-of-bound write and possible secure boot bypass

Published
August 13, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table? The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect their machine and to install the updates if they are not receiving automatic updates. Note that the general availability date for Windows 11, version 24H2 is scheduled for later this year.

Why is this Redhat CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in the Linux GRUB2 boot loader, a boot loader designed to support Secure Boot on systems that are running Linux. It is being documented in the Security Update Guide to announce that the latest builds of Windows are no longer vulnerable to this security feature bypass using the Linux GRUB2 boot loader. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.

Will this update affect my ability to boot Linux after applying this update? To address this security issue, Windows will apply a Secure Boot Advanced Targeting (SBAT) update to block vulnerable Linux boot loaders that could have an impact on Windows security. The SBAT value is not applied to dual-boot systems that boot both Windows and Linux and should not affect these systems. You might find that older Linux distribution ISOs will not boot. If this occurs, work with your Linux vendor to get an update. Update, September 19, 2024: To address a known issue on systems with dual booting for Windows and Linux, we have reconfigured the manner in which this fix can be applied. Starting with the September 10, 2024 security updates, the fix will not automatically apply the SBAT update to the firmware. Customers who have applied the August 13, 2024 security updates will have the SBAT update in firmware and will be protected. Customers who have devices with Windows system only and who have not applied the August updates and who want to be protected from this issue can either apply the August 13, 2024 updates or apply the September 10, 2024 updates and set the following registry key from an Administrator command prompt: reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x400 /f” Update, May 16, 2024: The security updates released on May 13, 2025 apply improvements to SBAT for the detection of Linux systems, and address the known issue with dual booting for Windows and Linux.

🎯 Affected products37

  • Azure Linux 3.0 ARM
  • Azure Linux 3.0 x64
  • CBL Mariner 1.0 ARM
  • CBL Mariner 1.0 x64
  • CBL Mariner 2.0 ARM
  • CBL Mariner 2.0 x64
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • +7 more not shown

✅ Remediation

KBgrub2 (CBL-Mariner) — fixed build 2.06-14 KBgrub2 (CBL-Mariner) — fixed build 2.06~rc1-9 KBgrub2 (CBL-Mariner) — fixed build 2.06-8 KB5055519 (Security Update) — fixed build 10.0.17763.7136 KB5055526 (Security Update) — fixed build 10.0.20348.3453 KB5041592 (Security Update) — fixed build 10.0.22000.3147 KB5055518 (Security Update) — fixed build 10.0.19044.5737 KB5055528 (Security Update) — fixed build 10.0.22621.5189 KB5055518 (Security Update) — fixed build 10.0.19045.5737 KB5055528 (Security Update) — fixed build 10.0.22631.5189 KB5055527 (Security Update) — fixed build 10.0.25398.1551 KB5055547 (Security Update) — fixed build 10.0.10240.20978 KB5055521 (Security Update) — fixed build 10.0.14393.7969 KB5055581 (Monthly Rollup) — fixed build 6.2.9200.25423 KB5055557 (Monthly Rollup) — fixed build 6.3.9600.22523 KB5055523 (Security Update) — fixed build 10.0.26100.3775

🔗 References (24)