CVE-2024-45783Improper Update of Reference Count in Grub2

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 96.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18

Description

A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue may lead to a NULL pointer access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages6 packages

🔴Vulnerability Details

2
GHSA
GHSA-4wxw-3vrc-3hmh: A flaw was found in grub22025-02-18
OSV
CVE-2024-45783: A flaw was found in grub22025-02-18

📋Vendor Advisories

3
Red Hat
grub2: fs/hfs+: refcount can be decremented twice2025-02-18
Microsoft
Grub2: fs/hfs+: refcount can be decremented twice2025-02-11
Debian
CVE-2024-45783: grub2 - A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus files...2024