Database/Firmware, BMC & network fabric

TPM 2.0 (S3 sleep PCR reset): Platform Configuration Registers can be reset without a full platform restart by abusing
Impact
Platform Configuration Registers can be reset without a full platform restart by abusing the S3 sleep path, letting an attacker replay chosen measurements into a TPM that should only ever accumulate them. The effect is that a machine which booted a tampered image can present PCR values identical to a clean boot, defeating sealed-storage unlock policies and remote attestation. Any control you built on 'the PCRs cannot lie' stops holding.
Who can reach it
Local attacker with the ability to put the system into and out of S3 sleep - so a tenant with root on a bare-metal node, or anyone with console access.
What to do
Platform firmware/BIOS update from the OEM (per node, reboot required) that correctly re-establishes the static root of trust across sleep. Practical compensating control on servers: disable S3 suspend entirely in BIOS, which most datacenter nodes never use anyway - a config-only change that eliminates the trigger. Do that first, then patch on the normal cycle.
References
Related entries
- GRUB2 (grub_malloc allocator): GRUB's allocator never checks the requested size for arithmetic overflow, so a tenantCVE-2020-14308 · GRUB2 (grub_malloc allocator)Medium
- GRUB2 (squashfs symlink parser): Integer overflow in grub_squash_read_symlink lets a crafted squashfs image driveCVE-2020-14309 · GRUB2 (squashfs symlink parser)Medium
- GRUB2 (read_section_from_string): Integer overflow while reading a section string overflows the heap and gives controlCVE-2020-14310 · GRUB2 (read_section_from_string)Medium
- GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heapCVE-2020-14311 · GRUB2 (ext2/ext4 symlink reader)Medium
- GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that functionCVE-2020-15706 · GRUB2 (script function redefinition)Medium
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldCVE-2021-3418 · GRUB2 (grub-install shim_lock regression)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.