Database/Firmware, BMC & network fabric
GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that function
Impact
Use-after-free when a GRUB script redefines a function while that function is executing. Gives arbitrary code execution in the bootloader from nothing more than a modified grub.cfg, which on most distros is not itself signature-checked.
Who can reach it
Anyone who can write grub.cfg - local root, or a previous bare-metal tenant. This is the classic BootHole shape: config file trusted more than it deserves.
What to do
grub2 package update + reboot per node. Also worth checking that grub.cfg is not writable from a tenant-reachable partition on your image layout.
References
Related entries
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldCVE-2021-3418 · GRUB2 (grub-install shim_lock regression)Medium
- Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU): IHISI is Insyde's own firmware-services interfaceCVE-2022-30773 · Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swappedCVE-2022-30774 · Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU): Firmware Volume Block services are the abstractionCVE-2022-31243 · Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU): A DMA race against the Platform Configuration Database SMICVE-2022-32266 · Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (SmmResourceCheckDxe input buffer, DMA TOCTOU): The sharpest irony in the batch: SmmResourceCheckDxeCVE-2022-32267 · Insyde InsydeH2O (SmmResourceCheckDxe input buffer, DMA TOCTOU)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.