Database/Firmware, BMC & network fabric
GRUB2 (read_section_from_string): Integer overflow while reading a section string overflows the heap and gives control
Impact
Integer overflow while reading a section string overflows the heap and gives control of GRUB before the kernel loads. Practical outcome is a Secure Boot bypass that survives an OS reinstall, because the compromise lives in the boot partition rather than the root filesystem.
Who can reach it
Local write access to boot-time data on the node - a previous tenant, an operator with remote-hands, or a BMC-mounted virtual disk.
What to do
grub2 package update + reboot. Follow with a dbx update, sequenced after every node is confirmed on the fixed binary. Config-only mitigation does not exist for this class.
References
Related entries
- GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heapCVE-2020-14311 · GRUB2 (ext2/ext4 symlink reader)Medium
- GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that functionCVE-2020-15706 · GRUB2 (script function redefinition)Medium
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldCVE-2021-3418 · GRUB2 (grub-install shim_lock regression)Medium
- Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU): IHISI is Insyde's own firmware-services interfaceCVE-2022-30773 · Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swappedCVE-2022-30774 · Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU): Firmware Volume Block services are the abstractionCVE-2022-31243 · Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.