Database/Firmware, BMC & network fabric
GNU GRUB 2 (serial command MMIO base address validation): GRUB's `serial` command accepts an MMIO base address without
Impact
GRUB's serial command accepts an MMIO base address without checking that it points at a real UART, so a write intended for a serial register can be aimed at GRUB's own memory. Clearing the grub_file_verifiers list this way turns off signature checking for subsequently loaded modules while GRUB still reports that lockdown is active. On a GPU node that means an attacker who already holds root or physical/management access can load unsigned code into the boot path and keep a measured-boot story that looks intact, which undermines the attestation operators rely on for confidential-computing nodes (SEV-SNP/TDX) and for proving a rented bare-metal GPU host was not tampered with between tenants. It does not give a tenant inside a container or VM anything new - GRUB configuration control is required.
Who can reach it
Local attacker who can already control GRUB's configuration or command line - practically host root, a compromised provisioning/PXE path, or console/BMC-level access to the boot menu. Authentication is required; there is no remote vector. CVSS vector records high privileges and high attack complexity.
What to do
Pick up the fixed grub2 package from your distribution once it ships the upstream commit (26beaa3b) that validates the serial MMIO base; applying it means rewriting the bootloader and rebooting the node, so it folds into a normal node-drain-and-reboot maintenance window rather than a live patch. Until then, treat GRUB config and the boot console as root-equivalent: password-protect the GRUB menu, restrict BMC/console access, and remember that affected shim/SBAT revocations may eventually require updating Secure Boot revocation lists as well. No distribution fixed versions are named in the record.
References
Related entries
- AMD processors - frequency scaling / power management: A remote or local attacker times operations and infers secretCVE-2022-23823 · AMD processors - frequency scaling / power managementMedium
- Intel processors - power management throttling: The Intel half of Hertzbleed: observable behaviour in power-managementCVE-2022-24436 · Intel processors - power management throttlingMedium
- Ampere Altra / Altra Max processors: The Arm-server variant of HertzbleedCVE-2022-35888 · Ampere Altra / Altra Max processorsMedium
- AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tagCVE-2023-34471 · AMI MegaRAC SPx (BMC cryptography / HMAC)Medium
- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: Debug code was shipped active in AMD's Video CoreCVE-2024-36319 · AMD Video Decoder Engine Firmware (VCN FW) - debug code left activeMedium
- EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorCVE-2024-38805 · EDK II NetworkPkg (IScsiDxe, iSCSI login response processing)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.