CVE-2025-0678
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 190
CWE ID 787
Summary
CVE-2025-0678 is a vulnerability affecting the grub2 system, which uses user-controlled parameters from squash4 filesystems to determine buffer sizes for data reading. The grub software incorrectly checks for integer overflows in these calculations, allowing a maliciously crafted filesystem to cause a heap-based out-of-bounds write during the direct_read() function. This vulnerability may result in the corruption of grub's critical data and potentially enable arbitrary code execution, bypassing secure boot protections.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gnu Grub2
- Red Hat Enterprise Linux
- Red Hat Openshift Container Platform
Affected Vendors
- Red Hat
- GNU