Back to Database
Status published
Unknown
CVE-2024-56738
GNU GRUB (aka GRUB2) through 2.12 does not use a...
Vulnerability Description
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-56738
Credits & Attribution
No credits recorded in the NVD database.
References
More from GNU
View All →CVE-2025-8746
GNU libopts __strstr_sse2 memory corruption
Medium
4.8
CVE-2025-8736
GNU cflow Lexer c.c yylex buffer overflow
Medium
4.8
CVE-2025-8735
GNU cflow Lexer c.c yylex null pointer dereference
Medium
4.8
CVE-2025-8225
GNU Binutils DWARF Section dwarf.c process_debug_info memory leak
Medium
4.8
CVE-2025-8224
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Medium
4.8
Affected Vendor
Affected Software
GRUB2
Vulnerable Versions:
2.00
Timeline
Official Publish:
December 29th, 2024
Last Modified:
December 31st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.