GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (squashfs symlink parser): Integer overflow in grub_squash_read_symlink lets a crafted squashfs image drive

CVE-2020-14309Firmware, BMC & network fabricBootHole familycurated

Impact

Integer overflow in grub_squash_read_symlink lets a crafted squashfs image drive a heap overflow inside GRUB. Attacker-chosen code runs before the kernel and before any measured-boot evidence the operator would trust, so an implant planted here is invisible to every agent running in the tenant OS.

Who can reach it

Requires control of a filesystem image GRUB will read - the boot partition on a node the attacker already had, or an image served over the provisioning path.

What to do

grub2 package update + reboot per node. Real closure needs the dbx revocation of the old signed GRUB, which is a separate and riskier rollout. On GPU nodes the reboot means draining running training jobs, so batch it with an existing maintenance window rather than doing it alone.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.