Database/Firmware, BMC & network fabric
GRUB2 (rmmod command): Use-after-free in the rmmod command
Impact
Use-after-free in the rmmod command. Unloading a module whose dependencies are still live leaves dangling pointers GRUB will later call through, which is a clean primitive for arbitrary pre-boot execution and another Secure Boot bypass.
Who can reach it
Local, via GRUB command line or a controlled grub.cfg. On a bare-metal fleet, any tenant who had console or root on the node.
What to do
grub2 package update + reboot per node. If you leave the GRUB command line unlocked on your image, set a GRUB password as a stopgap - it does not fix the bug but it removes the easiest path to it.
References
Related entries
- GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command lineCVE-2020-27749 · GRUB2 (grub_parser_split_cmdline)High
- AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsing: Insufficient validation when parsing OCACVE-2021-26406 · AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsingHigh
- Arista EOS (VXLAN match rule in IPv4 ACL): If an IPv4 access list contains a VXLAN match rule, that rule and every ruleCVE-2021-28505 · Arista EOS (VXLAN match rule in IPv4 ACL)High
- Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersCVE-2021-28508 · Arista EOS (TerminAttr / IPsec)High
- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBCVE-2021-3695 · GRUB2 (PNG reader)High
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBCVE-2021-3697 · GRUB2 (JPEG reader)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.