VDB

DEBIAN-CVE-2024-56738

DEBIAN-CVE-2024-56738 PUBLISHED CVSS 5.300000190734863 MEDIUM

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Debian:13grub2*, 0, 2.12-9
Debian:12grub22.06-13, 2.06-13, 2.06-13
Debian:14grub22.14, 2.12-9, 0
Debian:11grub22.06-13, 2.06-13, 2.06-14

Timeline

  • Dec 29, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›