CVE-2025-1125

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 787

Summary

CVE-2025-1125 is a vulnerability affecting the hfs filesystem module in GRUB. The issue arises when the module uses user-controlled parameters from the filesystem metadata to calculate buffer sizes without proper checks for integer overflows. Maliciously crafted filesystems can cause these buffer size calculations to overflow, leading the hfsplus_open_compressed_real() function to write past the intended buffer length. This flaw potentially allows corruption of GRUB's internal critical data, bypassing secure boot protections and paving the way for arbitrary code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share