CVE-2025-0678

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 190
CWE ID 787

Summary

CVE-2025-0678 is a vulnerability affecting the grub2 system, which uses user-controlled parameters from squash4 filesystems to determine buffer sizes for data reading. The grub software incorrectly checks for integer overflows in these calculations, allowing a maliciously crafted filesystem to cause a heap-based out-of-bounds write during the direct_read() function. This vulnerability may result in the corruption of grub's critical data and potentially enable arbitrary code execution, bypassing secure boot protections.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gnu Grub2
  • Red Hat Enterprise Linux
  • Red Hat Openshift Container Platform

Affected Vendors

  • Red Hat
  • GNU