CVE-2025-0689

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 120

Summary

CVE-2025-0689 is a vulnerability affecting the grub UDF filesystem module. The issue arises when the module assumes that the read size from the disk is smaller than its allocated buffer size while reading data from disk. However, this assumption is not always true, leading to a heap-based buffer overflow. An attacker could craft a filesystem image to exploit this vulnerability, potentially corrupting critical data and bypassing secure boot protections. The risk of arbitrary code execution is significant, making this a serious security concern.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share