Database/Firmware, BMC & network fabric
GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to start
CVSS 6.7CVE-2022-28736Firmware, BMC & network fabriccurated
Impact
Use-after-free in grub_cmd_chainloader when a chainloaded image fails to start. Gives pre-boot code execution and, in combination with the other 2022 bugs, a full Secure Boot bypass chain.
Who can reach it
Local, via GRUB command line or grub.cfg on a node the attacker has touched.
What to do
grub2 package update + reboot per node.
References
Related entries
- CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryCVE-2022-34301 · CryptoPro Secure Disk (signed UEFI bootloader)Medium
- New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootCVE-2022-34302 · New Horizon Datasys (signed UEFI bootloader)Medium
- Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeCVE-2022-34303 · Eurosoft (UK) Ltd (signed UEFI bootloader)Medium
- Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildCVE-2023-24932 · Windows Boot Manager (Secure Boot bypass)Medium
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
- CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformCVE-2023-3264 · CyberPower PowerPanel Enterprise DCIMMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.