← Vulnerability feed

Vulnerability record · CVE-2024-56737 · published 29 December 2024

CVE-2024-56737: Gnu grub2 heap-based buffer overflow vulnerability

Gnu · Grub2

GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.

8.8 CVSS 3.1 High EPSS 0.73% · top 47.7% CWE-122 · Heap-based buffer overflow
8.8CVSS 3.1 base score
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://savannah.gnu.org/bugs/?66599 Issue TrackingThird Party Advisory

Track CVE-2024-56737 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2022-2601Gnu grub2 heap-based buffer overflow vulnerabilityA buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size …EPSS 0.51%8.2CVE-2021-20233Gnu grub2 out-of-bounds write vulnerabilityA flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption tha…EPSS 0.61%8.2CVE-2020-25632Gnu grub2 use after free vulnerabilityA flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking …EPSS 1.2%8.2CVE-2020-10713Gnu grub2 classic buffer overflow vulnerabilityA flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw a…EPSS 1.7%8.1CVE-2022-28733Gnu grub2 vulnerabilityInteger underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() functio…EPSS 1.3%7.8CVE-2025-61662Gnu grub2 use after free vulnerabilityA Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remai…EPSS 0.20%7.8CVE-2025-0678Gnu grub2 integer overflow vulnerabilityA flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem …EPSS 0.28%7.8CVE-2024-45782Gnu grub2 out-of-bounds write vulnerabilityA flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2024-56737), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.