GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed buffer

CVE-2024-45782Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

An unbounded strcpy of the HFS volume name overflows a fixed buffer. About as direct a memory-corruption primitive as this codebase contains, and it fires on nothing more than attaching a crafted volume.

Who can reach it

Attacker-supplied HFS volume, including one presented over BMC virtual media.

What to do

grub2 package update + reboot. Strip the HFS module if you never boot Apple-formatted media, which on a GPU fleet is always.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.