Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gmj-v2m8-qffv

Опубликовано: 29 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

EPSS

Процентиль: 32%
0.00166
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 5.3
ubuntu
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

CVSS3: 6.5
redhat
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

CVSS3: 5.3
nvd
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

msrc
3 месяца назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

CVSS3: 5.3
debian
11 месяцев назад

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorit ...

EPSS

Процентиль: 32%
0.00166
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-208