GPU VulnDB

Database/Firmware, BMC & network fabric

New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure Boot

CVE-2022-34302Firmware, BMC & network fabricThree more bootloaderscurated

Impact

Signed bootloader with a built-in mechanism to bypass Secure Boot enforcement, described by researchers as more subtle than its siblings because it disables verification without obviously tampering with the chain. Yields a bootkit that measured boot will not flag.

Who can reach it

EFI System Partition write access on the target node.

What to do

dbx revocation, delivered via firmware or OS vendor update. No package fix exists because the vulnerable artifact is a signed third-party binary.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.