GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heap

CVE-2020-14311Firmware, BMC & network fabricBootHole familycurated

Impact

Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heap overflow in the bootloader. Because ext4 is what almost every Linux GPU node actually boots from, this one is reachable on stock images rather than exotic filesystems.

Who can reach it

Attacker controls the boot filesystem - realistically a tenant who had root on the box, or anyone who can attach media over the BMC.

What to do

grub2 package update + reboot per node; then the dbx revocation pass. Note that a node that PXE-boots a fresh image every provisioning cycle is not automatically safe - the vulnerable GRUB is in the image you serve, so fix the golden image too, not just running nodes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.