{"id":"CVE-2024-56738","details":"GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.","modified":"2026-04-10T05:15:13.170495Z","published":"2024-12-29T07:15:06.183Z","related":["SUSE-SU-2025:02705-1","SUSE-SU-2025:02706-1","SUSE-SU-2025:02724-1","SUSE-SU-2025:02725-1","SUSE-SU-2025:02727-1","SUSE-SU-2025:02772-1","SUSE-SU-2025:02813-1","SUSE-SU-2025:20654-1","SUSE-SU-2025:20863-1","SUSE-SU-2025:21212-1","SUSE-SU-2025:21223-1","openSUSE-SU-2025:15400-1","openSUSE-SU-2025:20163-1"],"references":[{"type":"REPORT","url":"https://savannah.gnu.org/bugs/?66603"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56738.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2.12"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}