CVE-2024-45782

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 787
CWE ID 120

Summary

CVE-2024-45782 is a vulnerability affecting the HFS filesystem in grub. The issue arises when the HFS filesystem driver performs an unvalidated strcpy() operation using a user-supplied volume name during grub_fs_mount(). This could potentially result in a heap-based out-of-bounds write, compromising grub's data integrity. Malicious actors could exploit this vulnerability to bypass secure boot protection.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gnu Grub2
  • Red Hat Enterprise Linux
  • Red Hat Openshift Container Platform

Affected Vendors

  • Red Hat
  • GNU