Database/Firmware, BMC & network fabric
GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted image
CVSS 6.7CVE-2024-45774Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write in GRUB's JPEG parser from a crafted image; possible Secure Boot bypass — part of the 2024-2025 GRUB2 vulnerability wave (73 issues)
Who can reach it
Local, ESP write
What to do
Coordinated GRUB2 + shim + dbx rollout across every distro image in the fleet. The distro-by-distro fan-out is the real cost: a neocloud offering multiple guest images has to rebuild all of them
References
Related entries
- GRUB2 (commands/extcmd): A failed allocation goes unchecked, so GRUB proceeds on a NULL pointer and its stateCVE-2024-45775 · GRUB2 (commands/extcmd)Medium
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionCVE-2024-45778 · GRUB2 (BFS filesystem parser)Medium
- GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of boundsCVE-2024-45780 · GRUB2 (tar filesystem parser)Medium
- GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFSCVE-2024-45781 · GRUB2 (UFS filesystem parser)Medium
- Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620CVE-2024-47976 · Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620…Medium
- Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystemCVE-2025-22397 · Dell iDRAC9 / iDRAC10 (path traversal)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.