CVE-2024-56738

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/12/2024
Last modified:
24/06/2025

Description

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* 2.12 (including)


References to Advisories, Solutions, and Tools