GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUB

CVE-2021-3695Firmware, BMC & network fabriccurated

Impact

A crafted PNG in the boot splash path causes an out-of-bounds write in GRUB. Boot logos and themes are attacker-writable data on almost every image, so this is a low-effort way to turn cosmetic files into pre-boot code execution.

Who can reach it

Anyone who can replace a theme/splash image on the boot partition - local root, previous tenant, or a tampered golden image.

What to do

grub2 package update + reboot. Strip custom boot themes from your golden image if you do not need them; it removes the attack surface entirely at zero operational cost.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.