Description
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-9gmj-v2m8-qffv: GNU GRUB (aka GRUB2) through 2↗2024-12-29 ▶ OSVCVE-2024-56738: GNU GRUB (aka GRUB2) through 2↗2024-12-29 ▶ CVEListCVE-2024-56738: GNU GRUB (aka GRUB2) through 2↗2024-12-29 ▶ 📋Vendor Advisories
3Red Hatgrub2: Observable Timing Discrepancy resulting side-channel attacks↗2024-12-29 ▶ MicrosoftGNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.↗2024-12-10 ▶ DebianCVE-2024-56738: grub2 - GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for gru...↗2024 ▶