CVE-2024-45778

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 190

Summary

CVE-2024-45778 is a newly discovered vulnerability affecting the BFS file system. A stack overflow issue can be triggered when reading a maliciously crafted BFS filesystem. This can result in an uncontrolled loop, leading to a crash of the grub2 bootloader. Successful exploitation of this vulnerability may enable an attacker to disrupt the boot process and potentially gain unauthorized access to a system. Users are advised to update their BFS file system and grub2 as soon as patches become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gnu Grub2
  • Red Hat Enterprise Linux
  • Red Hat Openshift Container Platform

Affected Vendors

  • Red Hat
  • GNU