Описание
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| grub2 | unfixed | package | ||
| grub2 | postponed | trixie | package | |
| grub2 | postponed | bookworm | package |
Примечания
https://savannah.gnu.org/bugs/?66603
EPSS
Процентиль: 32%
0.00166
Низкий
Связанные уязвимости
CVSS3: 5.3
ubuntu
11 месяцев назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVSS3: 6.5
redhat
11 месяцев назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVSS3: 5.3
nvd
11 месяцев назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
msrc
3 месяца назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
EPSS
Процентиль: 32%
0.00166
Низкий