Database/Firmware, BMC & network fabric
GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB font
CVE-2022-2601Firmware, BMC & network fabriccurated
Impact
Buffer overflow when constructing a glyph from a crafted GRUB font file. Fonts are unsigned data sitting in the boot partition on virtually every install, which makes this one of the cheapest Secure Boot bypasses in the family.
Who can reach it
Anyone who can write a font file to the boot partition - local root, prior tenant, or a poisoned image build.
What to do
grub2 package update + reboot. Fonts are rarely needed on a headless server image; dropping the graphical GRUB theme removes this surface outright.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.