VendorsGNUgrub2all versions
Vulnerabilities

GNU grub2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2019-14865
A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
Published 2019-11-29 · Analyzed
5.9EPSS 0.003
CVE-2024-45778
Grub2: fs/bfs: integer overflow in the bfs parser.
Published 2025-03-03 · Modified
5.5EPSS 0.003
CVE-2023-4693
Grub2: out-of-bounds read at fs/ntfs.c
Published 2023-10-25 · Modified
5.3EPSS 0.005
CVE-2024-56738
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Published 2024-12-29 · Analyzed
5.3EPSS 0.004
CVE-2021-46705
grub2-once uses fixed file name in /var/tmp
Published 2022-03-16 · Modified
5.1EPSS 0.002
CVE-2021-3695
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.
Published 2022-07-06 · Modified
4.5EPSS 0.005
CVE-2021-3981
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
Published 2022-03-08 · Modified
3.3EPSS 0.003
CVE-2024-1048
Grub2: grub2-set-bootflag can be abused by local (pseudo-)users
Published 2024-02-06 · Modified
3.3EPSS 0.003
← Prev2 / 2