{"id":"CVE-2024-49504","details":"grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.","modified":"2026-03-23T05:04:23.599996534Z","published":"2024-11-13T15:15:07Z","withdrawn":"2025-03-14T00:57:19.109515Z","related":["SUSE-SU-2025:0586-1","SUSE-SU-2025:20511-1","SUSE-SU-2025:20863-1","openSUSE-SU-2024:14464-1"],"references":[{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-49504"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-49504"}],"affected":[{"package":{"name":"grub2","ecosystem":"Debian:11","purl":"pkg:deb/debian/grub2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.04-20","2.06-1","2.06-10","2.06-11","2.06-12","2.06-13","2.06-13+hurd.1","2.06-13+hurd.2","2.06-14","2.06-2","2.06-2+hurd.1","2.06-2+hurd.2","2.06-2+hurd.3","2.06-2+hurd.4","2.06-2+hurd.5","2.06-2+hurd.6","2.06-2+hurd.7","2.06-2+hurd.8","2.06-3","2.06-3~deb10u1","2.06-3~deb10u2","2.06-3~deb10u3","2.06-3~deb10u4","2.06-3~deb11u1","2.06-3~deb11u2","2.06-3~deb11u4","2.06-3~deb11u5","2.06-3~deb11u6","2.06-4","2.06-4+hurd.1","2.06-5","2.06-6","2.06-7","2.06-8","2.06-8+hurd.1","2.06-8.1","2.06-9","2.12-1","2.12-1.1","2.12-1~bpo12+1","2.12-2","2.12-2~deb13u1","2.12-3","2.12-4","2.12-5","2.12~rc1-1","2.12~rc1-10","2.12~rc1-11","2.12~rc1-12","2.12~rc1-13","2.12~rc1-2","2.12~rc1-3","2.12~rc1-6","2.12~rc1-7","2.12~rc1-8","2.12~rc1-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49504.json"}},{"package":{"name":"grub2","ecosystem":"Debian:12","purl":"pkg:deb/debian/grub2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.06-13","2.06-13+deb12u1","2.06-13+hurd.1","2.06-13+hurd.2","2.06-14","2.12-1","2.12-1.1","2.12-1~bpo12+1","2.12-2","2.12-2~deb13u1","2.12-3","2.12-4","2.12-5","2.12~rc1-1","2.12~rc1-10","2.12~rc1-11","2.12~rc1-12","2.12~rc1-13","2.12~rc1-2","2.12~rc1-3","2.12~rc1-6","2.12~rc1-7","2.12~rc1-8","2.12~rc1-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49504.json"}},{"package":{"name":"grub2","ecosystem":"Debian:13","purl":"pkg:deb/debian/grub2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.06-13","2.06-13+deb13u1","2.06-13+hurd.1","2.06-13+hurd.2","2.06-14","2.12-1","2.12-1.1","2.12-1~bpo12+1","2.12-2","2.12-2~deb13u1","2.12-3","2.12-4","2.12-5","2.12~rc1-1","2.12~rc1-10","2.12~rc1-11","2.12~rc1-12","2.12~rc1-13","2.12~rc1-2","2.12~rc1-3","2.12~rc1-6","2.12~rc1-7","2.12~rc1-8","2.12~rc1-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49504.json"}}],"schema_version":"1.7.3"}