vulnerability

Debian: CVE-2024-45775: grub2 -- security update

Severity
5
CVSS
(AV:L/AC:M/Au:M/C:P/I:P/A:C)
Published
Feb 18, 2025
Added
May 15, 2025
Modified
May 17, 2026

Description

A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation fails, a NULL point will be processed by the parse_option() function, leading grub to crash or, in some rare scenarios, corrupt the IVT data.

Solutions

debian-upgrade-grub2no-fix-debian-deb-package
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.