Database/Firmware, BMC & network fabric
GRUB2 (HFS filesystem parser): Integer overflow computing internal buffer sizes from HFS metadata, leading to a heap
CVSS 6.4CVE-2025-1125Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Integer overflow computing internal buffer sizes from HFS metadata, leading to a heap out-of-bounds write.
Who can reach it
Attacker-supplied HFS volume, physical or virtual media.
What to do
grub2 package update + reboot; or build GRUB without HFS support.
References
Related entries
- GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed bufferCVE-2024-45782 · GRUB2 (HFS filesystem parser)High
- Dell OMSA: authenticated SSRF lets a low-privileged user reach systems behind the agentCVE-2026-81443 · Dell OpenManage Server Administrator (SSRF, authenticated)Medium
- GNU GRUB 2 (serial command MMIO base address validation): GRUB's `serial` command accepts an MMIO base address withoutCVE-2026-97876 · GNU GRUB 2 (serial command MMIO base address validation)Medium
- AMD processors - frequency scaling / power management: A remote or local attacker times operations and infers secretCVE-2022-23823 · AMD processors - frequency scaling / power managementMedium
- Intel processors - power management throttling: The Intel half of Hertzbleed: observable behaviour in power-managementCVE-2022-24436 · Intel processors - power management throttlingMedium
- Ampere Altra / Altra Max processors: The Arm-server variant of HertzbleedCVE-2022-35888 · Ampere Altra / Altra Max processorsMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.