Database/Firmware, BMC & network fabric
GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heap
Impact
Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heap overflow in the bootloader. Because ext4 is what almost every Linux GPU node actually boots from, this one is reachable on stock images rather than exotic filesystems.
Who can reach it
Attacker controls the boot filesystem - realistically a tenant who had root on the box, or anyone who can attach media over the BMC.
What to do
grub2 package update + reboot per node; then the dbx revocation pass. Note that a node that PXE-boots a fresh image every provisioning cycle is not automatically safe - the vulnerable GRUB is in the image you serve, so fix the golden image too, not just running nodes.
References
Related entries
- GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that functionCVE-2020-15706 · GRUB2 (script function redefinition)Medium
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldCVE-2021-3418 · GRUB2 (grub-install shim_lock regression)Medium
- Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU): IHISI is Insyde's own firmware-services interfaceCVE-2022-30773 · Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swappedCVE-2022-30774 · Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU): Firmware Volume Block services are the abstractionCVE-2022-31243 · Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU): A DMA race against the Platform Configuration Database SMICVE-2022-32266 · Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.