GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heap

CVE-2020-15707Firmware, BMC & network fabricBootHole familycurated

Impact

Integer overflows in the initrd command's size arithmetic corrupt GRUB's heap. Same end state as the rest of the family - unsigned code running pre-kernel with Secure Boot still claiming to be enforcing.

Who can reach it

Requires the attacker to control the initrd list, i.e. write access to boot configuration on the node.

What to do

grub2 package update + reboot. No config-only mitigation.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.