Database/Firmware, BMC & network fabric
GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptor
Impact
Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptor. In a datacenter this is not a 'someone walks up with a USB stick' story - the BMC presents virtual media as a USB device, so anyone with BMC credentials can trigger it entirely remotely.
Who can reach it
Physical USB, or - the one that matters - BMC virtual media, which turns this into a remote attack for anyone on the management VLAN with iDRAC/iLO/XCC credentials.
What to do
grub2 package update + reboot. Meaningful compensating control: disable virtual media on the BMC where you do not use it for provisioning, and keep the management network off any tenant-reachable path.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.