GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFS

CVE-2024-45781Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

Symlink name length is never validated, giving a heap out-of-bounds write in the UFS parser and a route to circumventing Secure Boot.

Who can reach it

Attacker-supplied UFS image on an attached or virtual disk.

What to do

grub2 package update + reboot. Red Hat noted no viable mitigation short of the update, so this is a patch-or-accept decision.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.