CVE-2024-56738
published 2024-12-29CVE-2024-56738: GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.39%
32.0th percentile
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | — | — |
| gnu | grub2 | <= 2.12 | — |
| gnu | grub2 | 2.00 – 2.12 | — |
| msrc | azl3_grub2_2.06-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-25_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-26_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-27_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grub2_2.06-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grub2_2.06-16_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_msrc6.7MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grub2: Observable Timing Discrepancy resulting side-channel attacks
vendor_redhat·2024-12-29·CVSS 5.3
CVE-2024-56738 [MEDIUM] CWE-208 grub2: Observable Timing Discrepancy resulting side-channel attacks
grub2: Observable Timing Discrepancy resulting side-channel attacks
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
A flaw was found in GRUB2. Affected versions of GRUB2 do not use a constant-time algorithm for grub_crypto_memcmp, which can allow side-channel attacks.
Statement: Due to the extremely limited conditions needed for exploitation, this vulnerability is classified as low severity. Due to GRUB using libgcrypt during HTTPS operations, there is potential for a side-channel attack that could enable an attacker to infer TLS session key information. However, because GRUB runs in a single-threaded context during boot, it eliminates the common attack vector of timing measurements across threads, so
Microsoft
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
vendor_msrc·2024-12-10·CVSS 6.7
CVE-2024-56738 [MEDIUM] CWE-208 GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Act
Debian
CVE-2024-56738: grub2 - GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for gru...
vendor_debian·2024·CVSS 5.3
CVE-2024-56738 [MEDIUM] CVE-2024-56738: grub2 - GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for gru...
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-9gmj-v2m8-qffv: GNU GRUB (aka GRUB2) through 2
ghsa_unreviewed·2024-12-29
CVE-2024-56738 [MEDIUM] CWE-208 GHSA-9gmj-v2m8-qffv: GNU GRUB (aka GRUB2) through 2
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
OSV
CVE-2024-56738: GNU GRUB (aka GRUB2) through 2
osv·2024-12-29·CVSS 5.3
CVE-2024-56738 [MEDIUM] CVE-2024-56738: GNU GRUB (aka GRUB2) through 2
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
No detection rules found.
No public exploits indexed.
2024-12-29
Published