Описание
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Ссылки
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.12 (включая)
cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00166
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-208
CWE-203
Связанные уязвимости
CVSS3: 5.3
ubuntu
11 месяцев назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVSS3: 6.5
redhat
11 месяцев назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
msrc
3 месяца назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVSS3: 5.3
debian
11 месяцев назад
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorit ...
EPSS
Процентиль: 32%
0.00166
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-208
CWE-203