Database/Firmware, BMC & network fabric
GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-free
CVSS 5.3CVE-2024-45783Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
A reference count can be decremented twice, producing a use-after-free. Lower severity on its own but a usable link in a chain with the write primitives in the same batch.
Who can reach it
Attacker-supplied HFS+ volume.
What to do
grub2 package update + reboot; or drop the module.
References
Related entries
- AMD CPU - stale TLB entries in SEV-SNP guests: A silicon bug lets a local admin-privileged attacker run an SEV-SNPCVE-2025-29934 · AMD CPU - stale TLB entries in SEV-SNP guestsMedium
- Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource letsCVE-2025-38742 · Dell iDRAC Service Module (iSM, incorrect permissions)Medium
- AMD CPU microcode - bound check: An improper bound check inside AMD CPU microcode lets a malicious **guest** write intoCVE-2025-52534 · AMD CPU microcode - bound checkMedium
- AMD Secure Processor - privilege check on write path: The ASP accepts an input value and performs a writeCVE-2025-54511 · AMD Secure Processor - privilege check on write pathMedium
- Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane trafficCVE-2025-7048 · Arista EOS (MACsec process)Medium
- Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master roleCVE-2026-73444 · Arista EOS VRRPv2 IP Authentication Header (IP-AH) authenticationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.