GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parser

CVE-2024-45779Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

Integer overflow producing a heap out-of-bounds read in the BeFS parser - leaks bootloader memory, useful for defeating any layout randomisation before pairing with a write primitive.

Who can reach it

Attacker-supplied BFS image.

What to do

grub2 package update + reboot; or strip unused filesystem modules from the GRUB build.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.