CVE-2021-3695General(fedoraproject / codeready_linux_builder)

LOWCVSS 4.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • codeready_linux_builder
  • developer_tools
  • enterprise_linux
  • enterprise_linux_eus

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
codeready_linux_builderdeveloper_toolsenterprise_linuxenterprise_linux_eusenterprise_linux_for_power_little_endianenterprise_linux_for_power_little_endian_eusenterprise_linux_server_ausenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutionsenterprise_linux_server_tusfedora

13 versions affected across 14 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 103-26
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • procles@vcprocles
    General

    @katanga_uranium @DoingFedTime 1. I think it's impossible right now to install Ubuntu with encrypted /boot, afaik the installer requires it to be unencrypted 2. CVE-2021-3695,3696,3697 — images CVE-2025-0678 (this one will be left afaik cuz kernel+gadget snap system kek) CVE-2025-1125,0684 etc. — filesystems

    Post summary

    The message lists several CVE identifiers (e.g., CVE-2021-3695, CVE-2025-0678) but does not provide exploitation details, patches, or proof of concept information, simply noting topics such as images, kernel gadgets, or filesystems.

    00010215
    43 followersView on X
CPE platform detail34 entries

34 of 34 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora36--
Appgnugrub2---
Appnetappontap_select_deploy_administration_utility---
Appredhatcodeready_linux_builder---
Appredhatdeveloper_tools1.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux8.1--
OSredhatenterprise_linux8.4--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_eus8.2--
OSredhatenterprise_linux_eus8.4--
OSredhatenterprise_linux_eus8.6--
OSredhatenterprise_linux_eus9.0--
OSredhatenterprise_linux_for_power_little_endian8.0--
OSredhatenterprise_linux_for_power_little_endian9.0--
OSredhatenterprise_linux_for_power_little_endian_eus8.2--
OSredhatenterprise_linux_for_power_little_endian_eus8.4--
OSredhatenterprise_linux_for_power_little_endian_eus8.6--
OSredhatenterprise_linux_for_power_little_endian_eus9.0--
OSredhatenterprise_linux_server_aus8.2--
OSredhatenterprise_linux_server_aus8.4--
OSredhatenterprise_linux_server_aus8.6--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.1--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.2--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.4--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.6--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions9.0--
OSredhatenterprise_linux_server_tus8.2--
OSredhatenterprise_linux_server_tus8.4--
OSredhatenterprise_linux_server_tus8.6--
Appredhatopenshift3.0--
Appredhatopenshift_container_platform4.10--
Appredhatopenshift_container_platform4.6--
Appredhatopenshift_container_platform4.9--

Explore more