{"id":"AZL-54709","summary":"CVE-2024-56738 affecting package grub2 2.06-26","details":"GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.","modified":"2026-04-21T04:35:40.146419Z","published":"2024-12-29T07:15:06Z","upstream":["CVE-2024-56738"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56738"}],"affected":[{"package":{"name":"grub2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/grub2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.06-26"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-54709.json"}}],"schema_version":"1.7.5"}