CVE-2024-2312: GNU GRUB2

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.

Affected products

  • GNU GRUB2: before 2.12-1ubuntu5 (fixed in 2.12-1ubuntu5)
  • Netapp Bootstrap OS: affected versions not specified

Published 2024-04-05. Last modified 2026-06-17.