Heap Overflow Vulnerability in GRUB2 Affects Linux Systems
CVE-2024-45780
6.7MEDIUM
Key Information:
- Vendor
- Gnu
- Vendor
- CVE Published:
- 3 March 2025
Summary
A vulnerability has been identified in GRUB2 where a flaw in the handling of tar file reading can lead to improper allocation verification. This oversight creates an opportunity for an attacker to craft a malicious tar file, potentially resulting in an overflow of the allocation length. Such an exploitation can result in heap out-of-bounds writes, which may allow the attacker to bypass the secure boot mechanism, thereby compromising system integrity.
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved