Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-56738

Опубликовано: 29 дек. 2024
Источник: debian
EPSS Низкий

Описание

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
grub2unfixedpackage
grub2postponedtrixiepackage
grub2postponedbookwormpackage

Примечания

  • https://savannah.gnu.org/bugs/?66603

EPSS

Процентиль: 32%
0.00166
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

CVSS3: 6.5
redhat
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

CVSS3: 5.3
nvd
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

msrc
3 месяца назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

suse-cvrf
3 месяца назад

Recommended update for grub2

EPSS

Процентиль: 32%
0.00166
Низкий