CVE-2025-0684
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Mar 3, 2025
CWE ID 787
Summary
CVE-2025-0684 is a vulnerability affecting the grub2 bootloader. It allows a maliciously crafted filesystem to cause integer overflows in buffer size calculations used by grub's reiserfs module. This results in a heap-based out-of-bounds write during data reading, potentially leading to the corruption of critical data and arbitrary code execution. The vulnerability can bypass secure boot protections, making it a significant security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.