Database/Firmware, BMC & network fabric
GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heap
CVE-2020-15707Firmware, BMC & network fabricBootHole familycurated
Impact
Integer overflows in the initrd command's size arithmetic corrupt GRUB's heap. Same end state as the rest of the family - unsigned code running pre-kernel with Secure Boot still claiming to be enforcing.
Who can reach it
Requires the attacker to control the initrd list, i.e. write access to boot configuration on the node.
What to do
grub2 package update + reboot. No config-only mitigation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.