Database/Firmware, BMC & network fabric
GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command line
CVE-2020-27749Firmware, BMC & network fabriccurated
Impact
Stack buffer overflow from variable expansion in the GRUB command line. Attacker gets code execution before the kernel and can therefore load an unsigned kernel or plant a bootkit that no in-OS EDR will see.
Who can reach it
Anyone who can type at the GRUB prompt or supply grub.cfg - local console, serial console server, or BMC KVM.
What to do
grub2 package update + reboot per node. Set a GRUB password and lock the serial/BMC console as a partial mitigation in the meantime.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.