CVE-2025-0689
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 120
Summary
CVE-2025-0689 is a vulnerability affecting the grub UDF filesystem module. The issue arises when the module assumes that the read size from the disk is smaller than its allocated buffer size while reading data from disk. However, this assumption is not always true, leading to a heap-based buffer overflow. An attacker could craft a filesystem image to exploit this vulnerability, potentially corrupting critical data and bypassing secure boot protections. The risk of arbitrary code execution is significant, making this a serious security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.