CVE-2024-45779
CVSS 3.1 Score 6 of 10 (medium)
Details
Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 125
CWE ID 190
Summary
CVE-2024-45779 is a newly identified vulnerability affecting the BFS file system driver in grub2. This issue arises due to a failure to validate the number of extent entries during file reading. An integer overflow can occur when processing a crafted or corrupted BFS filesystem, causing grub2 to read outside the bounds of the heap. The consequences of this vulnerability include sensitive data leakage or a grub2 crash.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gnu Grub2
Affected Vendors
- GNU