GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (read_section_from_string): Integer overflow while reading a section string overflows the heap and gives control

CVE-2020-14310Firmware, BMC & network fabricBootHole familycurated

Impact

Integer overflow while reading a section string overflows the heap and gives control of GRUB before the kernel loads. Practical outcome is a Secure Boot bypass that survives an OS reinstall, because the compromise lives in the boot partition rather than the root filesystem.

Who can reach it

Local write access to boot-time data on the node - a previous tenant, an operator with remote-hands, or a BMC-mounted virtual disk.

What to do

grub2 package update + reboot. Follow with a dbx update, sequenced after every node is confirmed on the fixed binary. Config-only mitigation does not exist for this class.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.