CVE Vulnerabilities

CVE-2024-2312

Published: Apr 05, 2024 | Modified: Apr 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntus peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.

References