Database/Firmware, BMC & network fabric
GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volume
CVSS 7.8CVE-2023-4692Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write parsing a crafted NTFS volume. Relevant to any node that dual-boots, mounts a Windows-formatted staging volume, or is handed a raw disk between tenants - the NTFS parser runs before anything verifies the disk's provenance.
Who can reach it
An attacker-supplied NTFS volume attached to the node, including via BMC virtual media.
What to do
grub2 package update + reboot per node. Where you never need NTFS, building GRUB without the module is a permanent fix rather than a patch treadmill.
References
Related entries
- GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memoryCVE-2023-4693 · GRUB2 (NTFS filesystem parser)Medium
- Phoenix SecureCore Technology 4 (boot splash screen image parsing): The firmware parses a user-supplied boot logo imageCVE-2023-5058 · Phoenix SecureCore Technology 4 (boot splash screen image parsing)High
- Linux kernel (drivers/infiniband/hw/hfi1): User SDMA requests with multiple payload buffers are read past the declaredCVE-2023-52474 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Linux kernel (drivers/infiniband/ulp/ipoib): A PKEY child interface created over netlink comes up with multiple TX/RXCVE-2023-52745 · Linux kernel (drivers/infiniband/ulp/ipoib)High
- ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM path: The video engine writes pastCVE-2023-52916 · ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM pathHigh
- Linux kernel (drivers/infiniband/core): A 32-bit advance counter in the core RDMA block iterator wraps when a singleCVE-2023-53026 · Linux kernel (drivers/infiniband/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.