CVE-2024-45780 Information
Mar 04, 2025
cve
Description
A flaw was found in grub2. When reading tar files grub2 allocates an internal buffer for the file name. However it fails to properly verify the allocation against possible integer overflows. It’s possible to cause the allocation length to overflow with a crafted tar file leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://access.redhat.com/security/cve/CVE-2024-45780 https://bugzilla.redhat.com/show_bug.cgi?id=2345856
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.7
Share on: