Database/Firmware, BMC & network fabric
GRUB2 (direct kernel boot without shim): When GRUB is booted directly by UEFI rather than chained through shim, it does
Impact
When GRUB is booted directly by UEFI rather than chained through shim, it does not verify the kernel signature at all. Any unsigned kernel boots with Secure Boot enabled and reporting healthy - so attestation and the operator's 'verified boot' control are simply false on those nodes. Confidential-computing claims built on measured boot become unverifiable.
Who can reach it
Applies to any node configured to load GRUB directly from the EFI System Partition. The attacker then only needs to drop a kernel, which any local root can do.
What to do
grub2 package update + reboot, and audit the boot configuration on every node to confirm shim is actually in the chain - a surprising number of custom/netboot images skip it. This is one of the few in this family where a config check is a genuine part of the fix, not just a workaround.
References
Related entries
- Cisco NX-OS (BGP MD5 authentication): BGP MD5 authentication can be bypassed, so an attacker can bring up a BGP sessionCVE-2020-3165 · Cisco NX-OS (BGP MD5 authentication)High
- Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS passwordCVE-2021-21522 · Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS password via the…High
- Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL neverCVE-2021-33627 · Insyde InsydeH2O (FwBlockServiceSmm)High
- InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OSCVE-2021-38489 · InsydeH2O UEFI firmware (HDD password stored in a UEFI variable)High
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedCVE-2022-28735 · GRUB2 (shim_lock verifier)High
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderCVE-2022-28737 · shim (handle_image PE loader)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.