HOMEVULNERABILITIESCVE-2021-3696
MEDIUM

CVE-2021-3696

CWE-787Published: July 6, 2022· Updated: Jun 17, 2026

4.5
CVSS v3.1

Official Description

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

NVD Source

Technical Analysis

CVE-2021-3696 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

From a weakness classification perspective (CWE-787): Out-of-bounds write vulnerabilities can lead to data corruption, crashes, or arbitrary code execution.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityHigh
Privileges Req.Low
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityLow
IntegrityLow
AvailabilityLow
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Vendors & Products

gnu1 product(s)
grub2
netapp1 product(s)
ontap select deploy administration utility
Red Hat11 product(s)
developer toolsopenshiftenterprise linuxenterprise linux eusenterprise linux for power little endianenterprise linux for power little endian eusenterprise linux server ausenterprise linux server for power little endian update services for sap solutionsenterprise linux server tusopenshift container platformcodeready linux builder
Source: NVD CPE · 33 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (6)

Quick Facts

CVE IDCVE-2021-3696
CVSS Score4.5 / 10
SeverityMEDIUM
WeaknessCWE-787
CISA KEVNo
Affected3 vendor(s)
PublishedJul 6, 2022

Related CVEs (CWE-787)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2021-3696 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.