Database/Firmware, BMC & network fabric
GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parser
CVSS 6.0CVE-2024-45779Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Integer overflow producing a heap out-of-bounds read in the BeFS parser - leaks bootloader memory, useful for defeating any layout randomisation before pairing with a write primitive.
Who can reach it
Attacker-supplied BFS image.
What to do
grub2 package update + reboot; or strip unused filesystem modules from the GRUB build.
References
Related entries
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionCVE-2024-45778 · GRUB2 (BFS filesystem parser)Medium
- AMD SEV-SNP - RMP write access during SNP initialization: There is a window during SEV-SNP initialization in which anCVE-2025-0033 · AMD SEV-SNP - RMP write access during SNP initializationMedium
- Intel CSME / SPS firmware (timing side channel): An observable timing discrepancy in CSME/SPS firmware allowsCVE-2025-20067 · Intel CSME / SPS firmware (timing side channel)Medium
- Intel E810 Ethernet controller firmware: Improper input validation in E810 firmware lets a privileged local user denyCVE-2025-24296 · Intel E810 Ethernet controller firmwareMedium
- Intel Ethernet Controller E810 (100GbE) firmware: Uncaught exception in 100GbE E810 firmware, reachable from privilegedCVE-2025-24851 · Intel Ethernet Controller E810 (100GbE) firmwareMedium
- Intel Ethernet Controller E810 firmware: Out-of-bounds write inside E810 firmware, reachable from a privileged Ring-0CVE-2025-27243 · Intel Ethernet Controller E810 firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.