CVE-2024-45774
Rocky Linux vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2024-45774) was discovered in GRUB2's JPEG parser. The vulnerability allows a specially crafted JPEG file to cause the JPEG parser to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. This flaw was discovered in February 2025 and affects GRUB2 systems (NVD, Red Hat CVE).

Technical details

The vulnerability is classified as a heap out-of-bounds write vulnerability (CWE-787) that occurs when processing JPEG files. The issue specifically involves an extra SOF0 marker in JPEG files that can lead to incorrect bounds checking in internal buffers. The vulnerability has been assigned a CVSS v3.1 base score of 6.7 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating local access is required but no user interaction is needed (NVD, GRUB Dev List).

Impact

The vulnerability's impact is severe as it could potentially allow an attacker to overwrite sensitive information and bypass secure boot protections. The out-of-bounds write capability could lead to memory corruption and potentially compromise the integrity of the boot process (Red Hat CVE, GRUB Dev List).

Mitigation and workarounds

The vulnerability has been addressed in the GRUB2 codebase with patches that prevent duplicate SOF0 markers in JPEG files. Updated versions of GRUB2 containing these fixes are being distributed by various vendors. Users are advised to apply the latest security updates when they become available from their respective distribution vendors (GRUB Dev List).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13020HIGH8.8
  • NixOSNixOS
  • MozillaFirefox-branding-upstream
NoYesNov 11, 2025
CVE-2025-59088HIGH8.6
  • Rocky LinuxRocky Linux
  • python3-kdcproxy
NoYesNov 12, 2025
CVE-2025-13019HIGH8.1
  • NixOSNixOS
  • firefox-x11
NoYesNov 11, 2025
CVE-2025-59089MEDIUM5.9
  • Rocky LinuxRocky Linux
  • idm:DL1::bind-dyndb-ldap
NoYesNov 12, 2025
CVE-2025-40185N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-devel-matched
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management