Logo
vulnerabilityCVE-2024-45780
Name
CVE-2024-45780
Source
NVD ( link)Debian ( link)
Description
A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
grub2
Exploitable

Vulnerability Ratings#


6.7
CVSSv31
6.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.12
Patched
buildroot
master
2.14
Not Affected
openwrt
master
2.12-r1
Exploitable
yocto
kirkstone
2.06
Exploitable
yocto
master
2.14
Not Affected
yocto
scarthgap
2.12
Exploitable

Resolved with patches#


grub2 (buildroot:2025.02.x)

#
Title
Author
Resolve
1
fs/tar: Integer overflow leads to heap OOB write
Lidong Chen <lidong.chen@oracle.com>
CVE-2024-45780