Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53381 | GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks. |
Tue, 24 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu grub2 |
|
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu grub2 |
Thu, 09 Jan 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | grub2: Observable Timing Discrepancy resulting side-channel attacks | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 31 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 29 Dec 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks. | |
| Weaknesses | CWE-208 | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-31T18:15:24.931Z
Reserved: 2024-12-29T00:00:00.000Z
Link: CVE-2024-56738
Updated: 2024-12-31T18:15:15.613Z
Status : Analyzed
Published: 2024-12-29T07:15:06.183
Modified: 2025-06-24T00:29:03.183
Link: CVE-2024-56738
OpenCVE Enrichment
No data.
EUVD