ZeroHour

CVE-2024-45777

CVSS 3.1
6.7 medium
EPSS
<1%p15
Published
()
Modified
Description

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

Vendors
gnuredhat
Products
grub2, openshift, enterprise linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.