CVE-2024-45779
published 2025-03-03CVE-2024-45779: An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number…
PriorityP427medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.26%
17.7th percentile
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.12-6 (forky) | grub2 2.12-6 (forky) |
| gnu | grub2 | <= 2.12 | — |
| gnu | grub2 | >= 0 < 2.12-6 | 2.12-6 |
| gnu | grub2 | >= 0 < 2.12-6 | 2.12-6 |
| msrc | azl3_grub2_2.06-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-25_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grub2_2.06-15_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_msrc4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Grub2: fs/bfs: integer overflow leads to heap oob read in the bfs parser
vendor_msrc·2025-03-11·CVSS 4.1
CVE-2024-45779 [MEDIUM] CWE-190 Grub2: fs/bfs: integer overflow leads to heap oob read in the bfs parser
Grub2: fs/bfs: integer overflow leads to heap oob read in the bfs parser
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refer
Red Hat
grub2: fs/bfs: Integer overflow leads to Heap OOB Read in the BFS parser
vendor_redhat·2025-02-18·CVSS 6.0
CVE-2024-45779 [MEDIUM] CWE-190 grub2: fs/bfs: Integer overflow leads to Heap OOB Read in the BFS parser
grub2: fs/bfs: Integer overflow leads to Heap OOB Read in the BFS parser
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensit
Debian
CVE-2024-45779: grub2 - An integer overflow flaw was found in the BFS file system driver in grub2. When ...
vendor_debian·2024·CVSS 6.0
CVE-2024-45779 [MEDIUM] CVE-2024-45779: grub2 - An integer overflow flaw was found in the BFS file system driver in grub2. When ...
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.12-6)
sid: resolved (fixed in 2.12-6)
trixie: resolved (fixed in 2.12-6)
OSV
CVE-2024-45779: An integer overflow flaw was found in the BFS file system driver in grub2
osv·2025-03-03·CVSS 6.0
CVE-2024-45779 [MEDIUM] CVE-2024-45779: An integer overflow flaw was found in the BFS file system driver in grub2
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.
GHSA
GHSA-qg4m-5hg4-34vq: An integer overflow flaw was found in the BFS file system driver in grub2
ghsa_unreviewed·2025-03-03
CVE-2024-45779 [MEDIUM] CWE-125 GHSA-qg4m-5hg4-34vq: An integer overflow flaw was found in the BFS file system driver in grub2
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.
No detection rules found.
No public exploits indexed.
2025-03-03
Published