Database/Firmware, BMC & network fabric
GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFS
CVSS 6.7CVE-2024-45781Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Symlink name length is never validated, giving a heap out-of-bounds write in the UFS parser and a route to circumventing Secure Boot.
Who can reach it
Attacker-supplied UFS image on an attached or virtual disk.
What to do
grub2 package update + reboot. Red Hat noted no viable mitigation short of the update, so this is a patch-or-accept decision.
References
Related entries
- Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620CVE-2024-47976 · Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620…Medium
- Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystemCVE-2025-22397 · Dell iDRAC9 / iDRAC10 (path traversal)Medium
- IBM Power Systems host firmware: crafted service-processor command leaks protected registersCVE-2026-19321 · IBM Power Systems host firmware (service processor register access path)Medium
- Junos mgd: null pointer dereference on an SSH configuration change crashes the management daemonCVE-2026-21901 · Juniper Junos OS / Junos OS Evolved management daemon (mgd)Medium
- HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmwareCVE-2018-7113 · HPE iLO 5 (firmware update security restriction bypass)Medium
- AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareCVE-2023-34473 · AMI MegaRAC SPx (BMC hard-coded credentials)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.