Database/Firmware, BMC & network fabric
GRUB2 (net/ip IPv4 reassembly): Integer underflow in grub_net_recv_ip4_packets from a crafted IP packet
Impact
Integer underflow in grub_net_recv_ip4_packets from a crafted IP packet. This one matters far more than the filesystem bugs for a GPU cloud, because it is reachable over the network during PXE boot - an attacker who can answer on the provisioning VLAN owns the node before any OS, tenant, or agent exists.
Who can reach it
Anyone who can put packets on the provisioning/PXE network while a node is netbooting. No credentials, no prior access to the node.
What to do
grub2 package update + reboot, and update the netboot GRUB image you actually serve - patching running nodes does nothing if the TFTP/HTTP-served binary is stale. Compensating control: put provisioning on an isolated L2 segment with DHCP snooping, and do not let tenant workloads share it.
References
Related entries
- ATEN PE8108 switched PDU: A restricted (non-admin) user account on the PDU's web interface can control outletsCVE-2023-25409 · ATEN PE8108 switched PDUHigh
- AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionCVE-2023-34336 · AMI MegaRAC SPx (IPMI handler)High
- Lenovo XClarity Controller (XCC) - user account API: A read-only XCC user can change any other user's password throughCVE-2023-4606 · Lenovo XClarity Controller (XCC) - user account APIHigh
- OpenBMC phosphor-net-ipmid: unauthenticated RAKP handler leaves default key, allowing BMC login bypassCVE-2026-16141 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RAKP session authentication)High
- IBM PowerVM partition firmware: unauthenticated attacker on the boot VLAN can substitute a netboot imageCVE-2026-17414 · IBM PowerVM partition firmware (network boot)High
- IBM Power Systems Firmware: BMC/FSP root can write arbitrary hardware control registers and take the hostCVE-2026-17429 · IBM Power Systems Firmware (BMC/FSP-to-host register interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.