Database/Firmware, BMC & network fabric
GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed buffer
CVSS 7.5CVE-2024-45782Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
An unbounded strcpy of the HFS volume name overflows a fixed buffer. About as direct a memory-corruption primitive as this codebase contains, and it fires on nothing more than attaching a crafted volume.
Who can reach it
Attacker-supplied HFS volume, including one presented over BMC virtual media.
What to do
grub2 package update + reboot. Strip the HFS module if you never boot Apple-formatted media, which on a GPU fleet is always.
References
Related entries
- GRUB2 (HFS filesystem parser): Integer overflow computing internal buffer sizes from HFS metadata, leading to a heapCVE-2025-1125 · GRUB2 (HFS filesystem parser)Medium
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageCVE-2024-50062 · Linux kernel (drivers/infiniband/ulp/rtrs)High
- Linux kernel (drivers/infiniband/core): A peer that drives enough connection churn across a node's IB port pushes theCVE-2024-50095 · Linux kernel (drivers/infiniband/core)High
- Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk): An untrusted segcount from the client is multipliedCVE-2024-53151 · Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk)High
- AMI AptioV UEFI BIOS: A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code executionCVE-2024-54084 · AMI AptioV UEFI BIOSHigh
- Insyde InsydeH2O (UsbCoreDxe SMM module): Another SMM callout in the USB core driverCVE-2024-55567 · Insyde InsydeH2O (UsbCoreDxe SMM module)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.