GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grubcryptomemcmp and thus allows side-channel attacks.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56738.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "2.12" } ] } ]