ThreatCluster

Multiple Vulnerabilities Found in grub2 Affecting Data Integrity and Availability

First seen 26 Feb 2026, 09:11 UTC Api.Msrc.Microsoft 63

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2021-20225 and CVE-2021-20233, were discovered in grub2 versions prior to 2.06. CVE-2021-20225 allows attackers to write past the end of a heap, while CVE-2021-20233 enables memory corruption due to incorrect length calculations in menu rendering code. Both flaws pose risks to data confidentiality, integrity, and system availability.

Timeline

2021-03-03
CVE-2021-20225 published
2021-03-03
CVE-2021-20233 published
2026-02-26
Information published about vulnerabilities