CVE-2024-45779

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 125
CWE ID 190

Summary

CVE-2024-45779 is a newly identified vulnerability affecting the BFS file system driver in grub2. This issue arises due to a failure to validate the number of extent entries during file reading. An integer overflow can occur when processing a crafted or corrupted BFS filesystem, causing grub2 to read outside the bounds of the heap. The consequences of this vulnerability include sensitive data leakage or a grub2 crash.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share