CVE Vulnerabilities

CVE-2024-45779

This vulnerability is marked as RESERVED by NVD. This means that the CVE-ID is reserved for future use by the CVE Numbering Authority (CNA) or a security researcher, but the details of it are not yet publicly available yet.

This page will reflect the classification results once they are available through NVD.

Any vendor information available is shown as below.

Redhat

grub2: fs/bfs: Integer overflow leads to Heap OOB Read in the BFS parser

Mitigation

Do not run grub2 in an untrusted environment, specifically with a BFS file system image.

Ubuntu

fs/bfs: Integer overflow leads to Heap OOB Read (Write?) in the BFS parser.

Affected Software List

Name Vendor Version
Grub2 Ubuntu/esm-infra-legacy/trusty update incompatible with kernel
Grub2 Ubuntu/upstream TBD
Grub2-signed Ubuntu/upstream TBD
Grub2-signed Ubuntu/devel TBD
Grub2-signed Ubuntu/esm-infra/xenial TBD
Grub2-signed Ubuntu/noble TBD
Grub2-signed Ubuntu/jammy TBD
Grub2-signed Ubuntu/oracular TBD
Grub2-signed Ubuntu/esm-infra-legacy/trusty update incompatible with kernel
Grub2-signed Ubuntu/esm-infra/bionic TBD
Grub2-signed Ubuntu/focal TBD
Grub2-unsigned Ubuntu/oracular TBD
Grub2-unsigned Ubuntu/upstream TBD
Grub2-unsigned Ubuntu/devel TBD
Grub2-unsigned Ubuntu/esm-infra/bionic TBD
Grub2-unsigned Ubuntu/esm-infra/xenial TBD
Grub2-unsigned Ubuntu/focal TBD
Grub2-unsigned Ubuntu/jammy TBD
Grub2-unsigned Ubuntu/noble TBD