GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install could

CVE-2021-3418Firmware, BMC & network fabriccurated

Impact

GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install could produce an installation that skips shim and therefore skips kernel signature verification. Nodes you believed you had already fixed silently regress when they are rebuilt with a newer GRUB.

Who can reach it

Not directly attacker-triggered - it is a build/provisioning regression that reopens the earlier bypass. The attacker then needs only local root.

What to do

grub2 package update + reboot, and re-verify the boot chain on any node reimaged between the original BootHole fix and this one. Worth a fleet-wide audit script that asserts shim is in the chain, not a one-off check.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.