CVE-2024-45776 Details
Description
When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes. This flaw allows an attacker to leak sensitive data or overwrite critical data, possibly circumventing secure boot protections.
A vulnerability exists in GRUB2 when processing language .mo files. The issue arises from the lack of proper validation of integer calculations related to buffer allocation, allowing a specially crafted .mo file to cause an overflow. This overflow can lead to out-of-bounds memory reads and writes, creating a risk of leaking sensitive information or overwriting critical data. Such memory corruption could potentially bypass secure boot protections.
Users can apply the GRUB2 update available through the Red Hat Enterprise Linux 9 erratum RHSA-2025:6990 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 18, 2025CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:16154 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2025:6990 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/security/cve/CVE-2024-45776 | [email protected] | AdvisoryVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2339182 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat Enterprise Linux | ~9 ~9.6 |
CPE
Remediation
| |
| grub2 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2025 | CVE Modified | [email protected] |
| May 13, 2025 | CVE Modified | [email protected] |
| Feb 18, 2025 | New CVE Received | [email protected] |
Volerion