Database/Firmware, BMC & network fabric
GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB font
CVSS 8.6CVE-2022-2601Firmware, BMC & network fabriccurated
Impact
Buffer overflow when constructing a glyph from a crafted GRUB font file. Fonts are unsigned data sitting in the boot partition on virtually every install, which makes this one of the cheapest Secure Boot bypasses in the family.
Who can reach it
Anyone who can write a font file to the boot partition - local root, prior tenant, or a poisoned image build.
What to do
grub2 package update + reboot. Fonts are rarely needed on a headless server image; dropping the graphical GRUB theme removes this surface outright.
References
Related entries
- Intel AMT / Standard Manageability firmware: Improper input validation in AMT/ISM firmware, scored high becauseCVE-2022-36392 · Intel AMT / Standard Manageability firmwareHigh
- GRUB2 (font engine, blit_comb): Integer underflow when rendering certain unicode sequences writes out of boundsCVE-2022-3775 · GRUB2 (font engine, blit_comb)High
- Cisco NX-OS (MPLS traffic handling / netstack): Crafted MPLS traffic restarts netstack, which stops the switchCVE-2024-20267 · Cisco NX-OS (MPLS traffic handling / netstack)High
- Cisco NX-OS (eBGP implementation): An unauthenticated remote attacker can wedge the switch through the eBGPCVE-2024-20321 · Cisco NX-OS (eBGP implementation)High
- Cisco NX-OS (DHCPv6 relay agent): A crafted DHCPv6 packet takes the switch out. Relevant because DHCP relay is normallyCVE-2024-20446 · Cisco NX-OS (DHCPv6 relay agent)High
- Linux bnxt_en driver (TX BD bd_cnt field masking): The 5-bit bd_cnt field in the transmit buffer descriptorCVE-2025-22108 · Linux bnxt_en driver (TX BD bd_cnt field masking)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.