Database/Firmware, BMC & network fabric
GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUB
CVSS 7.5CVE-2021-3697Firmware, BMC & network fabriccurated
Impact
Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUB. This is the GRUB-side sibling of the firmware image-parser problem that LogoFAIL exploited a year later - same idea, different layer.
Who can reach it
Attacker-writable splash/theme file on the boot partition.
What to do
grub2 package update + reboot. Removing boot theme images from the image is a real mitigation here.
References
Related entries
- IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCCVE-2021-38960 · IBM OpenBMC OP920 / OP930 / OP940High
- OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportCVE-2021-39295 · OpenBMC phosphor-net-ipmid (IPMI LAN+)High
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedCVE-2021-46983 · Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ)High
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aCVE-2022-23818 · AMD SEV-SNP - VM_HSAVE_PA MSR validationHigh
- OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webCVE-2022-2809 · OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end)High
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.