A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issues and eventually allowing an attacker to circumvent secure boot protections.
CVE ID: CVE-2024-45781
Vendor: Red Hat
Product: Red Hat Enterprise Linux 7
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 3.49% (scored less or equal to compared to others)
EPSS Date: 2025-03-19 (when was this score calculated)