A flaw was found in grub2. Grub's dump command is not...
Moderate severity
Unreviewed
Published
Feb 19, 2025
to the GitHub Advisory Database
•
Updated Feb 19, 2025
Description
Published by the National Vulnerability Database
Feb 19, 2025
Published to the GitHub Advisory Database
Feb 19, 2025
Last updated
Feb 19, 2025
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.
References