A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issues and eventually allowing an attacker to circumvent secure boot protections.
References
Configurations
No configuration.
History
13 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-787 | |
Summary |
|
18 Feb 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-18 20:15
Updated : 2025-05-13 20:15
NVD link : CVE-2024-45781
Mitre link : CVE-2024-45781
CVE.ORG link : CVE-2024-45781
JSON object : View
Products Affected
No product.
CWE
CWE-787
Out-of-bounds Write