Database/Firmware, BMC & network fabric
GRUB2 (font engine, blit_comb): Integer underflow when rendering certain unicode sequences writes out of bounds
CVSS 8.6CVE-2022-3775Firmware, BMC & network fabriccurated
Impact
Integer underflow when rendering certain unicode sequences writes out of bounds. Same class as the glyph-construction bug and shipped in the same advisory wave - if you patched one you probably need both.
Who can reach it
Crafted font or text rendered by GRUB, reachable by anyone who can write boot-partition content.
What to do
grub2 package update + reboot. Verify your distro's package covers both font CVEs, not just the first.
References
Related entries
- Cisco NX-OS (MPLS traffic handling / netstack): Crafted MPLS traffic restarts netstack, which stops the switchCVE-2024-20267 · Cisco NX-OS (MPLS traffic handling / netstack)High
- Cisco NX-OS (eBGP implementation): An unauthenticated remote attacker can wedge the switch through the eBGPCVE-2024-20321 · Cisco NX-OS (eBGP implementation)High
- Cisco NX-OS (DHCPv6 relay agent): A crafted DHCPv6 packet takes the switch out. Relevant because DHCP relay is normallyCVE-2024-20446 · Cisco NX-OS (DHCPv6 relay agent)High
- Linux bnxt_en driver (TX BD bd_cnt field masking): The 5-bit bd_cnt field in the transmit buffer descriptorCVE-2025-22108 · Linux bnxt_en driver (TX BD bd_cnt field masking)High
- Intel AMT and Intel Standard Manageability firmware (current CSME generations): Out-of-bounds write in AMT/ISM firmwareCVE-2025-32008 · Intel AMT and Intel Standard Manageability firmware (current CSME generations)High
- Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loadsCVE-2025-59887 · Eaton UPS Companion (EUC) software installerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.