GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to start

CVE-2022-28736Firmware, BMC & network fabriccurated

Impact

Use-after-free in grub_cmd_chainloader when a chainloaded image fails to start. Gives pre-boot code execution and, in combination with the other 2022 bugs, a full Secure Boot bypass chain.

Who can reach it

Local, via GRUB command line or grub.cfg on a node the attacker has touched.

What to do

grub2 package update + reboot per node.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.