Database/Firmware, BMC & network fabric
GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of bounds
CVE-2024-45780Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Integer overflow in the tarfs module writes out of bounds. Tar archives are a normal part of initrd and provisioning workflows, so this is more reachable in practice than the exotic filesystem parsers.
Who can reach it
Attacker-supplied tar image parsed by GRUB during boot.
What to do
grub2 package update + reboot.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.