yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-56737
Component Overview
Vulnerability Overview
Name
CVE-2024-56737
Source
NVD (
link
)
Debian (
link
)
Description
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
CWEs
CWE-122
Published Date
Dec 29, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://savannah.gnu.org/bugs/?66599
Issue Tracking
Analysis
#
Affected Component
Analysis
grub
Exploitable
Vulnerability Ratings
#
8.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
grub2
buildroot
2025.02.x
2.12
Patched
grub2
buildroot
master
2.14
Not Affected
grub2
openwrt
master
2.12-r1
Exploitable
grub2
openwrt
openwrt-25.12
2.12-r1
Exploitable
grub
yocto
master
2.14
Not Affected
grub
yocto
scarthgap
2.12
Exploitable
Resolved with patches
#
grub2 (buildroot:2025.02.x)
#
Title
Author
Resolve
1
fs/hfs: Fix stack OOB write with grub_strcpy()
B Horn <b@horn.uk>
CVE-2024-45782
CVE-2024-56737