Database/Firmware, BMC & network fabric
GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed buffer
CVE-2024-45782Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
An unbounded strcpy of the HFS volume name overflows a fixed buffer. About as direct a memory-corruption primitive as this codebase contains, and it fires on nothing more than attaching a crafted volume.
Who can reach it
Attacker-supplied HFS volume, including one presented over BMC virtual media.
What to do
grub2 package update + reboot. Strip the HFS module if you never boot Apple-formatted media, which on a GPU fleet is always.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.