cbcvebase.
CVE-2024-2312
published 2024-04-05

CVE-2024-2312: GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to…

PriorityP429medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.4th percentile
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_based_gnu_grub< 2.12-1ubuntu52.12-1ubuntu5
debiangrub2< grub2 2.12-2 (forky)grub2 2.12-2 (forky)
gnugrub2< 2.12-1ubuntu52.12-1ubuntu5
gnugrub2>= 0 < 2.12-22.12-2
gnugrub2>= 0 < 2.12-22.12-2
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
msrcazl3_grub2_2.06-24_on_azure_linux_3.0
msrccbl2_grub2_2.06-14_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian6.7LOW
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.