HomeDefectsLIN1023-9960
Fixed

LIN1023-9960 : Security Advisory - grub - CVE-2024-56738

Created: Dec 28, 2024    Updated: Oct 27, 2025
Resolved Date: Oct 19, 2025
Found In Version: 10.23.30.1
Fix Version: 10.23.30.19
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

CVEs