Database/Firmware, BMC & network fabric
GRUB2 (squashfs symlink parser): Integer overflow in grub_squash_read_symlink lets a crafted squashfs image drive
Impact
Integer overflow in grub_squash_read_symlink lets a crafted squashfs image drive a heap overflow inside GRUB. Attacker-chosen code runs before the kernel and before any measured-boot evidence the operator would trust, so an implant planted here is invisible to every agent running in the tenant OS.
Who can reach it
Requires control of a filesystem image GRUB will read - the boot partition on a node the attacker already had, or an image served over the provisioning path.
What to do
grub2 package update + reboot per node. Real closure needs the dbx revocation of the old signed GRUB, which is a separate and riskier rollout. On GPU nodes the reboot means draining running training jobs, so batch it with an existing maintenance window rather than doing it alone.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.