CVE-2024-45780
Last modified
CVE-2024-45780 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Grub2 | <= 2.12 |
References
- https://access.redhat.com/security/cve/CVE-2024-45780Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2345856Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45780?
How severe is CVE-2024-45780?
How do I fix CVE-2024-45780?
Are you affected by CVE-2024-45780?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
