Database/Firmware, BMC & network fabric
GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command line
CVSS 7.5CVE-2020-27749Firmware, BMC & network fabriccurated
Impact
Stack buffer overflow from variable expansion in the GRUB command line. Attacker gets code execution before the kernel and can therefore load an unsigned kernel or plant a bootkit that no in-OS EDR will see.
Who can reach it
Anyone who can type at the GRUB prompt or supply grub.cfg - local console, serial console server, or BMC KVM.
What to do
grub2 package update + reboot per node. Set a GRUB password and lock the serial/BMC console as a partial mitigation in the meantime.
References
Related entries
- AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsing: Insufficient validation when parsing OCACVE-2021-26406 · AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsingHigh
- Arista EOS (VXLAN match rule in IPv4 ACL): If an IPv4 access list contains a VXLAN match rule, that rule and every ruleCVE-2021-28505 · Arista EOS (VXLAN match rule in IPv4 ACL)High
- Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersCVE-2021-28508 · Arista EOS (TerminAttr / IPsec)High
- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBCVE-2021-3695 · GRUB2 (PNG reader)High
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBCVE-2021-3697 · GRUB2 (JPEG reader)High
- IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCCVE-2021-38960 · IBM OpenBMC OP920 / OP930 / OP940High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.