CVE-2025-1125
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2025-1125 is a vulnerability affecting the hfs filesystem module in GRUB. The issue arises when the module uses user-controlled parameters from the filesystem metadata to calculate buffer sizes without proper checks for integer overflows. Maliciously crafted filesystems can cause these buffer size calculations to overflow, leading the hfsplus_open_compressed_real() function to write past the intended buffer length. This flaw potentially allows corruption of GRUB's internal critical data, bypassing secure boot protections and paving the way for arbitrary code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.