Database/Firmware, BMC & network fabric
GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG path
CVE-2021-3696Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write on the grayscale PNG path. Same shape as the colour path but a separate code path that the first patch did not cover - relevant if you patched early and stopped.
Who can reach it
Attacker-supplied boot splash image.
What to do
grub2 package update + reboot. Confirm your package version covers this one specifically, not just the headline PNG CVE.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.