VYPR
Unrated severityNVD Advisory· Published Mar 3, 2025· Updated Mar 24, 2026

Grub2: fs/bfs: integer overflow in the bfs parser.

CVE-2024-45778

Description

A stack overflow in GRUB2's BFS file system parser allows an attacker with physical access to cause a denial of service via a crafted BFS filesystem.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack overflow in GRUB2's BFS file system parser allows an attacker with physical access to cause a denial of service via a crafted BFS filesystem.

Vulnerability

A stack overflow vulnerability exists in GRUB2's BFS file system parser. When reading a crafted BFS file system, an uncontrolled loop can occur, causing GRUB2 to crash. This issue affects versions of grub2 prior to the fix [1][2].

Exploitation

An attacker with physical access to the system can boot from a specially crafted BFS filesystem, triggering the uncontrolled loop and stack overflow, leading to a crash. No additional authentication or privileges are required [1][2].

Impact

Successful exploitation results in a denial of service, causing GRUB2 to crash and preventing the system from booting. The attacker achieves no code execution or privilege escalation, only a crash [1][2].

Mitigation

The vulnerability is fixed in updated grub2 packages. Users should apply the latest updates from their distribution. No workaround exists. The CVE is not currently listed in KEV [1][2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

31

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.