CVE-2024-2312: GNU GRUB2
Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
Affected products
- GNU GRUB2: before 2.12-1ubuntu5 (fixed in 2.12-1ubuntu5)
- Netapp Bootstrap OS: affected versions not specified
Published 2024-04-05. Last modified 2026-06-17.