CVE-2024-45780
CBL Mariner vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2024-45780) was discovered in GRUB2's tar file handling mechanism. The flaw was found in February 2025 and affects GRUB2 versions up to 2.12. The vulnerability stems from GRUB2's failure to properly verify buffer allocation against integer overflows when processing tar files (GRUB Devel, NVD).

Technical details

The vulnerability occurs when GRUB2 allocates an internal buffer for file names while reading tar files. The allocation process fails to properly verify against possible integer overflows, which can lead to a heap out-of-bounds write condition. The vulnerability has been assigned a CVSS v3.1 base score of 6.7 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating local access requirements with high privileges needed (NVD).

Impact

The vulnerability's exploitation can lead to a heap out-of-bounds write, which could allow an attacker to circumvent secure boot protections. This poses a significant security risk as it could potentially compromise the integrity of the boot process and bypass security mechanisms designed to protect the system during boot (GRUB Devel, Ubuntu Security).

Mitigation and workarounds

The vulnerability has been fixed in GRUB2 version 2.12-7 and later. Users are advised to update to the patched version. Full mitigation requires updated shim with latest SBAT (Secure Boot Advanced Targeting) data provided by distributions and vendors. The revocation of broken artifacts will be done with SBAT only, and UEFI revocation list (dbx) will not be used (GRUB Devel).

Additional resources


SourceThis report was generated using AI

Related CBL Mariner vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-62689HIGH8.7
  • NixOSNixOS
  • libmicrohttpd-devel
NoYesNov 10, 2025
CVE-2025-59777HIGH8.7
  • NixOSNixOS
  • libmicrohttpd-doc
NoYesNov 10, 2025
CVE-2025-47913HIGH7.5
  • PackerPacker
  • container-tools:rhel8::buildah-tests
NoYesNov 13, 2025
CVE-2024-47866HIGH7.5
  • CBL MarinerCBL Mariner
  • ceph
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management