Heap Overflow Vulnerability in GRUB2 Affects Linux Systems
CVE-2024-45780

6.7MEDIUM

Key Information:

Vendor
Gnu
Vendor
CVE Published:
3 March 2025

Summary

A vulnerability has been identified in GRUB2 where a flaw in the handling of tar file reading can lead to improper allocation verification. This oversight creates an opportunity for an attacker to craft a malicious tar file, potentially resulting in an overflow of the allocation length. Such an exploitation can result in heap out-of-bounds writes, which may allow the attacker to bypass the secure boot mechanism, thereby compromising system integrity.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.