Database/Firmware, BMC & network fabric
GRUB2 (cutmem command): The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carve
Impact
The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carve memory regions out of the map GRUB hands the kernel. Used to remove the regions that hold verification state, which downgrades a verified boot to an unverified one without tripping anything.
Who can reach it
Local privileged user at the GRUB shell.
What to do
grub2 package update + reboot. This is the lockdown-coverage class of bug: the fix is that the command is now refused when Secure Boot is on, so there is no config workaround short of a GRUB password.
References
Related entries
- Intel Ethernet 700 Series Controller firmware (access control): Insufficient access control inside 700-series NICCVE-2020-8692 · Intel Ethernet 700 Series Controller firmware (access control)Medium
- Intel BIOS firmware: Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalateCVE-2021-0157 · Intel BIOS firmwareMedium
- Intel SGX SDK (asynchronous exit / exception handling): SmashEx: an asynchronous exception delivered at the rightCVE-2021-0186 · Intel SGX SDK (asynchronous exit / exception handling)Medium
- GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parserCVE-2021-20225 · GRUB2 (short-form option parser)Medium
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeCVE-2021-20233 · GRUB2 (option quoting)Medium
- InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resourcesCVE-2021-43614 · Insyde InsydeH2O (PlatformLangCodes UEFI variable handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.