Database/Firmware, BMC & network fabric
GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to start
CVE-2022-28736Firmware, BMC & network fabriccurated
Impact
Use-after-free in grub_cmd_chainloader when a chainloaded image fails to start. Gives pre-boot code execution and, in combination with the other 2022 bugs, a full Secure Boot bypass chain.
Who can reach it
Local, via GRUB command line or grub.cfg on a node the attacker has touched.
What to do
grub2 package update + reboot per node.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.