Database/Firmware, BMC & network fabric
GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heap
CVSS 5.7CVE-2020-15707Firmware, BMC & network fabricBootHole familycurated
Impact
Integer overflows in the initrd command's size arithmetic corrupt GRUB's heap. Same end state as the rest of the family - unsigned code running pre-kernel with Secure Boot still claiming to be enforcing.
Who can reach it
Requires the attacker to control the initrd list, i.e. write access to boot configuration on the node.
What to do
grub2 package update + reboot. No config-only mitigation.
References
Related entries
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathCVE-2021-3696 · GRUB2 (PNG grayscale reader)Medium
- AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soCVE-2023-34472 · AMI MegaRAC SPx (BMC web interface, HTTP header handling)Medium
- AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASPCVE-2024-21981 · AMD Secure Processor - cryptographic key usage controlMedium
- Intel TDX: insufficient verification of data authenticity in the ring 0 interface leaks trust-domain dataCVE-2025-31356 · Intel TDX (hypervisor-facing ring 0 interface)Medium
- Caliptra Core ROM: TOCTOU in update-reset lets compromised MCU firmware bypass secure boot silentlyCVE-2026-11835 · Caliptra Core ROM (UpdateResetFlow staging-address validation)Medium
- Intel processors (indirect branch prediction): Spectre v2: an attacker trains the indirect branch predictor so that aCVE-2017-5715 · Intel processors (indirect branch prediction)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.