Information disclosure in grub - CVE-2024-49504

 

Information disclosure in grub - CVE-2024-49504

Published: February 19, 2025


Vulnerability identifier: #VU104090
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-49504
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
grub
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
SmartFabric Manager
APEX Cloud Platform for Microsoft Azure
grub2-efi-aa64-modules
grub2
grub2-debuginfo
grub2-debugsource
grub2-efi-aa64
grub2-efi-aa64-cdboot
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grub2-common
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-help
grub2-pc-modules
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2-tools-efi
grub2-powerpc-ieee1275-extras
grub2-s390x-emu-debug
grub2-i386-xen-extras
grub2-i386-efi
grub2-x86_64-xen-debug
grub2-powerpc-ieee1275
grub2-systemd-sleep-plugin
grub2-x86_64-efi
grub2-snapper-plugin
grub2-i386-pc
grub2-arm64-efi
grub2-s390x-emu
grub2-x86_64-xen
grub2-branding-upstream
grub2-x86_64-efi-extras
grub2-i386-pc-extras
grub2-i386-efi-extras
grub2-i386-pc-debug
grub2-i386-efi-debug
grub2-s390x-emu-extras
grub2-i386-xen-debug
grub2-powerpc-ieee1275-debug
grub2-arm64-efi-debug
grub2-i386-xen
grub2-arm64-efi-extras
grub2-x86_64-efi-debug
grub2-x86_64-xen-extras
APEX Cloud Platform for Red Hat OpenShift

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an error in grub implementation. A local user with access to the grub shell can access files on the encrypted disks.


How to mitigate CVE-2024-49504

Install updates from vendor's website.

Sources