Database/Firmware, BMC & network fabric
GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memory
CVSS 5.3CVE-2023-4693Firmware, BMC & network fabriccurated
Impact
Out-of-bounds read in the same NTFS path leaks GRUB heap memory. On its own it is an information leak, but it is the ASLR-defeating half that makes the paired write bug reliably exploitable.
Who can reach it
Attacker-supplied NTFS volume, physical or via BMC virtual media.
What to do
grub2 package update + reboot. Same as its sibling - dropping the NTFS module from your build is the durable answer on a Linux-only fleet.
References
Related entries
- GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volumeCVE-2023-4692 · GRUB2 (NTFS filesystem parser)High
- Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal letsCVE-2023-6032 · Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPSMedium
- Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS givesCVE-2024-0171 · Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race)Medium
- Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is notCVE-2024-27891 · Arista EOS (MACsec with egress ACLs)Medium
- Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedCVE-2024-31157 · Intel UEFI firmware (OutOfBandXML module)Medium
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationCVE-2024-38303 · Dell PowerEdge 14G Intel BIOS (improper input validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.