HOMEVULNERABILITIESCVE-2021-3695
MEDIUM

CVE-2021-3695

CWE-787Published: July 6, 2022· Updated: Jun 17, 2026

4.5
CVSS v3.1

Official Description

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

NVD Source

Technical Analysis

CVE-2021-3695 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

From a weakness classification perspective (CWE-787): Out-of-bounds write vulnerabilities can lead to data corruption, crashes, or arbitrary code execution.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityHigh
Privileges Req.Low
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityLow
IntegrityLow
AvailabilityLow
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Vendors & Products

Fedora1 product(s)
fedora
gnu1 product(s)
grub2
netapp1 product(s)
ontap select deploy administration utility
Red Hat11 product(s)
developer toolsopenshiftenterprise linuxenterprise linux eusenterprise linux for power little endianenterprise linux for power little endian eusenterprise linux server ausenterprise linux server for power little endian update services for sap solutionsenterprise linux server tusopenshift container platformcodeready linux builder
Source: NVD CPE · 34 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (6)

Quick Facts

CVE IDCVE-2021-3695
CVSS Score4.5 / 10
SeverityMEDIUM
WeaknessCWE-787
CISA KEVNo
Affected4 vendor(s)
PublishedJul 6, 2022

Related CVEs (CWE-787)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2021-3695 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.