Beveiligingsadvies

CVE-2024-45776

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-18 19:25:45
Laatst bijgewerkt 2026-06-29 22:53:52
Toegewezen door redhat
CVSS-score 6.7
Status PUBLISHED

Beschrijving

When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes. This flaw allows an attacker to leak sensitive data or overwrite critical data, possibly circumventing secure boot protections.