Database/Firmware, BMC & network fabric
GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memory
CVE-2023-4693Firmware, BMC & network fabriccurated
Impact
Out-of-bounds read in the same NTFS path leaks GRUB heap memory. On its own it is an information leak, but it is the ASLR-defeating half that makes the paired write bug reliably exploitable.
Who can reach it
Attacker-supplied NTFS volume, physical or via BMC virtual media.
What to do
grub2 package update + reboot. Same as its sibling - dropping the NTFS module from your build is the durable answer on a Linux-only fleet.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.