CVE-2025-0690
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Feb 24, 2025
Updated: Mar 5, 2025
CWE ID 787
Summary
CVE-2025-0690 is a vulnerability affecting the read command, which is used to read keyboard input. The issue lies in the way the input length is kept in a 32-bit integer value and used to reallocate the line buffer. With a large enough line, this variable can overflow, resulting in an out-of-bounds write in the heap-based buffer. This vulnerability can be exploited to corrupt critical data in grub, potentially leading to a secure boot bypass.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share