GNU GRUB2 2.12

CPE Details

GNU GRUB2 2.12
2.12
2023-12-16
02h56 +00:00
2023-12-16
02h56 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnu:grub2:2.12:*:*:*:*:*:*:*

Informations

Vendor

gnu

Product

grub2

Version

2.12

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-0678 2025-03-03 17h05 +00:00 A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciously crafted filesystem may lead some of those buffer size calculations to overflow, causing it to perform a grub_malloc() operation with a smaller size than expected. As a result, the direct_read() will perform a heap based out-of-bounds write during data reading. This flaw may be leveraged to corrupt grub's internal critical data and may result in arbitrary code execution, by-passing secure boot protections.
7.8
High
CVE-2024-45782 2025-03-03 17h05 +00:00 A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without properly validating the volume name's length. This issue may read to a heap-based out-of-bounds writer, impacting grub's sensitive data integrity and eventually leading to a secure boot protection bypass.
7.8
High
CVE-2024-45779 2025-03-03 14h25 +00:00 An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.
6
Medium