Database/Firmware, BMC & network fabric
GRUB2 (squashfs symlink parser): Integer overflow in grub_squash_read_symlink lets a crafted squashfs image drive
Impact
Integer overflow in grub_squash_read_symlink lets a crafted squashfs image drive a heap overflow inside GRUB. Attacker-chosen code runs before the kernel and before any measured-boot evidence the operator would trust, so an implant planted here is invisible to every agent running in the tenant OS.
Who can reach it
Requires control of a filesystem image GRUB will read - the boot partition on a node the attacker already had, or an image served over the provisioning path.
What to do
grub2 package update + reboot per node. Real closure needs the dbx revocation of the old signed GRUB, which is a separate and riskier rollout. On GPU nodes the reboot means draining running training jobs, so batch it with an existing maintenance window rather than doing it alone.
References
Related entries
- GRUB2 (read_section_from_string): Integer overflow while reading a section string overflows the heap and gives controlCVE-2020-14310 · GRUB2 (read_section_from_string)Medium
- GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heapCVE-2020-14311 · GRUB2 (ext2/ext4 symlink reader)Medium
- GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that functionCVE-2020-15706 · GRUB2 (script function redefinition)Medium
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldCVE-2021-3418 · GRUB2 (grub-install shim_lock regression)Medium
- Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU): IHISI is Insyde's own firmware-services interfaceCVE-2022-30773 · Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swappedCVE-2022-30774 · Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.