CVE-2025-0624 Information
Description
A flaw was found in grub2. During the network boot process when trying to search for the configuration file grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step it fails to consider the environment variable length when allocating the internal buffer resulting in an out-of-bounds write. If correctly exploited this issue may result in remote code execution through the same network segment grub is searching for the boot information which can be used to by-pass secure boot protections.
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Reference
https://access.redhat.com/security/cve/CVE-2025-0624 https://bugzilla.redhat.com/show_bug.cgi?id=2346112
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.6
Share on: