GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUB

CVE-2021-3697Firmware, BMC & network fabriccurated

Impact

Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUB. This is the GRUB-side sibling of the firmware image-parser problem that LogoFAIL exploited a year later - same idea, different layer.

Who can reach it

Attacker-writable splash/theme file on the boot partition.

What to do

grub2 package update + reboot. Removing boot theme images from the image is a real mitigation here.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.