GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
2024-12-29T07:15:06.183
2025-06-24T00:29:03.183
Analyzed
[email protected]
CVSSv3.1: 5.3 (MEDIUM)