GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruption

CVE-2024-45778Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

Integer overflow in the BeFS parser leads to heap corruption. Nobody runs BFS in production, which is exactly the point: GRUB compiles in filesystem modules you will never mount, and each one is reachable from an attacker-supplied disk image.

Who can reach it

Attacker-supplied filesystem image on a disk or virtual media the node will parse.

What to do

grub2 package update + reboot. The structural fix is to build GRUB with only the filesystem modules you actually boot from - it deletes a whole recurring CVE class from your fleet.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.