GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (HTTP chunked transfer): Out-of-bounds write handling chunked HTTP responses during HTTP boot

CVE-2022-28734Firmware, BMC & network fabriccurated

Impact

Out-of-bounds write handling chunked HTTP responses during HTTP boot. An attacker who can answer or MITM the HTTP boot request executes code in the bootloader on a node that has not booted an OS yet - the cleanest possible foothold on a bare-metal fleet.

Who can reach it

Network position on the provisioning path during HTTP boot: rogue DHCP, DNS spoofing, or a compromised provisioning server.

What to do

grub2 package update + reboot, and replace the served netboot binary. If you HTTP-boot, move to HTTPS boot with a pinned CA and isolate the provisioning VLAN - the transport was the actual weakness here.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.