Database/Firmware, BMC & network fabric
GRUB2 (gettext / message catalogue): Second integer overflow in the same translation path, producing a heap
CVSS 7.5CVE-2024-45777Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Second integer overflow in the same translation path, producing a heap out-of-bounds write and pre-boot code execution.
Who can reach it
Attacker-supplied locale catalogue on the boot partition.
What to do
grub2 package update + reboot; covered by the same distro update as the rest of the batch.
References
Related entries
- GRUB2 (gettext / message catalogue): Integer overflow reading a crafted translation catalogue gives bothCVE-2024-45776 · GRUB2 (gettext / message catalogue)High
- GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed bufferCVE-2024-45782 · GRUB2 (HFS filesystem parser)High
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageCVE-2024-50062 · Linux kernel (drivers/infiniband/ulp/rtrs)High
- Linux kernel (drivers/infiniband/core): A peer that drives enough connection churn across a node's IB port pushes theCVE-2024-50095 · Linux kernel (drivers/infiniband/core)High
- Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk): An untrusted segcount from the client is multipliedCVE-2024-53151 · Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk)High
- AMI AptioV UEFI BIOS: A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code executionCVE-2024-54084 · AMI AptioV UEFI BIOSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.