GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of bounds

CVE-2024-45780Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

Integer overflow in the tarfs module writes out of bounds. Tar archives are a normal part of initrd and provisioning workflows, so this is more reachable in practice than the exotic filesystem parsers.

Who can reach it

Attacker-supplied tar image parsed by GRUB during boot.

What to do

grub2 package update + reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.