Database/Firmware, BMC & network fabric
GRUB2 (HTTP chunked transfer): Out-of-bounds write handling chunked HTTP responses during HTTP boot
Impact
Out-of-bounds write handling chunked HTTP responses during HTTP boot. An attacker who can answer or MITM the HTTP boot request executes code in the bootloader on a node that has not booted an OS yet - the cleanest possible foothold on a bare-metal fleet.
Who can reach it
Network position on the provisioning path during HTTP boot: rogue DHCP, DNS spoofing, or a compromised provisioning server.
What to do
grub2 package update + reboot, and replace the served netboot binary. If you HTTP-boot, move to HTTPS boot with a pinned CA and isolate the provisioning VLAN - the transport was the actual weakness here.
References
Related entries
- Arm Trusted Firmware-A through v2.8, X.509 certificate parser used by Trusted Board Boot (get_ext, auth_nvctr)CVE-2022-47630 · Arm Trusted Firmware-A through v2.8, X.509 certificate parser used by Trusted Board Boot (get_ext, auth_nvctr)High
- AMD SMM module: heap overflow yields SMM code execution when chained with an SPI flash write flawCVE-2023-20577 · AMD platform firmware SMM module (EPYC server and Instinct MI300A BIOS)High
- shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bitCVE-2023-40548 · shim (verify_sbat_section)High
- Dell OMSA: unauthenticated SSRF turns the management agent into a proxy into the management VLANCVE-2026-81446 · Dell OpenManage Server Administrator (SSRF, unauthenticated)High
- Intel SGX (L1 terminal fault on enclave pages): Speculative execution lets code outside an enclave read the enclave'sCVE-2018-3615 · Intel SGX (L1 terminal fault on enclave pages)High
- AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASPCVE-2022-23817 · AMD Secure Processor Secure OS - memory buffer checkingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.