HomeDefault status
unknown
2.00 (custom)
affected
Description
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
Problem types
CWE-208 Observable Timing Discrepancy
Product status
2.00 (custom)