Database/Firmware, BMC & network fabric
GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volume
CVE-2023-4692Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write parsing a crafted NTFS volume. Relevant to any node that dual-boots, mounts a Windows-formatted staging volume, or is handed a raw disk between tenants - the NTFS parser runs before anything verifies the disk's provenance.
Who can reach it
An attacker-supplied NTFS volume attached to the node, including via BMC virtual media.
What to do
grub2 package update + reboot per node. Where you never need NTFS, building GRUB without the module is a permanent fix rather than a patch treadmill.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.