CVE-2023-4949: GNU Grub

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

Affected products

  • GNU Grub: up to and including 0.97
  • Xen Xen: affected versions not specified

Published 2023-11-10. Last modified 2026-06-17.