VDB

DEBIAN-CVE-2024-45777

DEBIAN-CVE-2024-45777 PUBLISHED CVSS 6.699999809265137 MEDIUM

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

Risk Scores

CVSS 3.1
6.699999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13grub20, 0
Debian:14grub20, 0
Debian:12grub22.06-13+hurd.2, 2.06-14, 2.12-1
Debian:11grub22.12-7, 2.12-8, 2.12-9

Timeline

  • Feb 19, 2025 CVE Published
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›