Required CVE Record Information
Description
A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.6 | HIGH | 3.1 | CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Product Status
Learn moreVersions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
Versions 1 Total
Default Status: affected
unaffected
References 17 Total
- access.redhat.com: RHSA-2025:2521 vendor-advisory
- access.redhat.com: RHSA-2025:2653 vendor-advisory
- access.redhat.com: RHSA-2025:2655 vendor-advisory
- access.redhat.com: RHSA-2025:2675 vendor-advisory
- access.redhat.com: RHSA-2025:2784 vendor-advisory
- access.redhat.com: RHSA-2025:2799 vendor-advisory
- access.redhat.com: RHSA-2025:2867 vendor-advisory
- access.redhat.com: RHSA-2025:2869 vendor-advisory
- access.redhat.com: RHSA-2025:3297 vendor-advisory
- access.redhat.com: RHSA-2025:3301 vendor-advisory
- access.redhat.com: RHSA-2025:3367 vendor-advisory
- access.redhat.com: RHSA-2025:3396 vendor-advisory
- access.redhat.com: RHSA-2025:3573 vendor-advisory
- access.redhat.com: RHSA-2025:3577 vendor-advisory
- access.redhat.com: RHSA-2025:3780 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-0624 vdb-entry
- bugzilla.redhat.com: RHBZ#2346112 issue-tracking