Database/Firmware, BMC & network fabric
GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUB
Impact
A crafted PNG in the boot splash path causes an out-of-bounds write in GRUB. Boot logos and themes are attacker-writable data on almost every image, so this is a low-effort way to turn cosmetic files into pre-boot code execution.
Who can reach it
Anyone who can replace a theme/splash image on the boot partition - local root, previous tenant, or a tampered golden image.
What to do
grub2 package update + reboot. Strip custom boot themes from your golden image if you do not need them; it removes the attack surface entirely at zero operational cost.
References
Related entries
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBCVE-2021-3697 · GRUB2 (JPEG reader)High
- IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCCVE-2021-38960 · IBM OpenBMC OP920 / OP930 / OP940High
- OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportCVE-2021-39295 · OpenBMC phosphor-net-ipmid (IPMI LAN+)High
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedCVE-2021-46983 · Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ)High
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aCVE-2022-23818 · AMD SEV-SNP - VM_HSAVE_PA MSR validationHigh
- OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webCVE-2022-2809 · OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.