Description

A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as input without properly validating the volume name's length. This issue may read to a heap-based out-of-bounds writer, impacting grub's sensitive data integrity and eventually leading to a secure boot protection bypass.

INFO

Published Date :

2025-03-03T17:05:25.397Z

Last Modified :

2025-11-14T01:33:52.131Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-45782 vulnerability.

Vendors Products
Gnu
  • Grub2
Redhat
  • Enterprise Linux
  • Openshift
  • Openshift Container Platform

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact