Database/Firmware, BMC & network fabric
GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parser
CVSS 6.7CVE-2021-20225Firmware, BMC & network fabriccurated
Impact
Heap out-of-bounds write in the short-form option parser. Another arbitrary-write primitive inside the signed bootloader, usable to load unsigned code with Secure Boot enabled.
Who can reach it
Local, via GRUB command line or grub.cfg.
What to do
grub2 package update + reboot per node, followed by the dbx pass if you are actually revoking old binaries.
References
Related entries
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeCVE-2021-20233 · GRUB2 (option quoting)Medium
- InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resourcesCVE-2021-43614 · Insyde InsydeH2O (PlatformLangCodes UEFI variable handling)Medium
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startCVE-2022-28736 · GRUB2 (chainloader)Medium
- CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryCVE-2022-34301 · CryptoPro Secure Disk (signed UEFI bootloader)Medium
- New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootCVE-2022-34302 · New Horizon Datasys (signed UEFI bootloader)Medium
- Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeCVE-2022-34303 · Eurosoft (UK) Ltd (signed UEFI bootloader)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.