CVE-2024-45779 is an integer overflow vulnerability in the grub2 BFS file system driver. It allows a specially crafted or corrupted BFS filesystem to cause a heap out-of-bounds read when grub2 attempts to read a file with an indirect extent map, affecting gnu grub2. The vulnerability has a CVSS score of 6.0 (Medium), indicating a local attack vector with low attack complexity, requiring high privileges to exploit, and potentially leading to sensitive data leakage or a system crash. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.12CPE matchmatch criteria | cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.