yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-56738
Component Overview
Vulnerability Overview
Name
CVE-2024-56738
Source
NVD (
link
)
Debian (
link
)
Description
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CWEs
CWE-208
CWE-203
Published Date
Dec 29, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://savannah.gnu.org/bugs/?66603
Issue Tracking
Analysis
#
Affected Component
Analysis
grub
Exploitable
Vulnerability Ratings
#
5.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
grub2
buildroot
2025.02.x
2.12
Patched
grub2
buildroot
master
2.14
Not Affected
grub2
openwrt
master
2.12-r1
Exploitable
grub2
openwrt
openwrt-25.12
2.12-r1
Exploitable
grub
yocto
master
2.14
Not Affected
grub
yocto
scarthgap
2.12
Exploitable
Resolved with patches
#
grub2 (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Constant-time grub_crypto_memcmp()
Gary Lin <glin@suse.com>
CVE-2024-56738