VDB
BDU%3A2025-03837
BDU%3A2025-03837
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость компонента tar Handler загрузчика операционных систем Grub2, позволяющая нарушителю обойти механизм безопасной загрузки
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Erich Boleyn, Сообщество свободного программного обеспечения, ООО «Ред Софт», АО «НТЦ ИТ РОСА» | Suse Linux Enterprise Desktop, Suse Linux Enterprise Server, SUSE Linux Enterprise Module for Basesystem, SUSE CaaS Platform, SUSE Linux Enterprise Point of Sale, SUSE Linux Enterprise Module for Server Applications, SUSE OpenStack Cloud Crowbar, SUSE Enterprise Storage, HPE Helion Openstack, Grub2, SUSE Manager Proxy, SUSE Manager Retail Branch Server, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, SUSE Manager Server, SUSE Linux Enterprise Micro, SUSE Linux Enterprise Real Time, openSUSE Leap Micro, РОСА ХРОМ (запись в едином реестре российских программ №1607), SUSE Manager Proxy Module |
Timeline
- Apr 7, 2025 CVE Published
- Sep 30, 2025 CVE Updated
References
- https://abf.rosa.ru/advisories/ROSA-SA-2025-3000 url
- https://access.redhat.com/security/cve/CVE-2024-45780 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2345856 url
- https://www.suse.com/security/cve/CVE-2024-45780.html url
- https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html url
- https://www.openwall.com/lists/oss-security/2025/02/18/3 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://security-tracker.debian.org/tracker/CVE-2024-45780 advisory