### Vulnerability Key Information Overview #### Vulnerability ID and Associated CVE - **Vulnerability ID**: Bug 1991685 - **Associated CVE**: CVE-2021-3695 #### Affected Products and Versions - **Product**: grub2 - **Fixed Version**: grub 2.12 #### Vulnerability Description - **Vulnerability Type**: Crafted PNG grayscale images may lead to out-of-bounds write - **Impact**: An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. #### Vulnerability Severity - **Priority**: medium - **Severity**: medium #### Vulnerability Status and Timeline - **Status**: CLOSED ERRATA - **Reported Time**: 2021-08-09 17:19 UTC - **Last Closed Time**: 2022-06-16 21:07:12 UTC #### Vulnerability Remediation and Affected Products - **Remediation Method**: Fixed via RHSA, with security advisories released for different Red Hat Enterprise Linux versions. - **Affected Product Versions**: - Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions - Red Hat Enterprise Linux 8.4 Extended Update Support - Red Hat Enterprise Linux 9 - Red Hat Enterprise Linux 8 - Red Hat Enterprise Linux 8.2 Extended Update Support