Database/Firmware, BMC & network fabric
GRUB2 (commands/gpg): Module unload leaves registered hooks behind, so GRUB later calls through freed function pointers
CVSS 6.4CVE-2025-0622Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Module unload leaves registered hooks behind, so GRUB later calls through freed function pointers. Notable because the affected module is the one meant to verify signatures - the bug is in the verification machinery itself.
Who can reach it
Local, via GRUB command sequences or grub.cfg.
What to do
grub2 package update + reboot. Part of the same February 2025 distro update as the rest of the batch.
References
Related entries
- GRUB2 (UFS symlink handling): Integer overflow on symlink handling in UFS gives a heap out-of-bounds write and a pathCVE-2025-0677 · GRUB2 (UFS symlink handling)Medium
- GRUB2 (ReiserFS symlink handling): Same symlink integer-overflow pattern in the ReiserFS parserCVE-2025-0684 · GRUB2 (ReiserFS symlink handling)Medium
- GRUB2 (JFS symlink handling): Symlink integer overflow in the JFS parser producing a heap out-of-bounds writeCVE-2025-0685 · GRUB2 (JFS symlink handling)Medium
- GRUB2 (romfs symlink handling): Symlink integer overflow in the romfs parser producing a heap out-of-bounds writeCVE-2025-0686 · GRUB2 (romfs symlink handling)Medium
- GRUB2 (UDF filesystem parser): Heap buffer overflow in grub_udf_read_blockCVE-2025-0689 · GRUB2 (UDF filesystem parser)Medium
- GRUB2 (read command): Integer overflow in the read command's accumulator writes out of boundsCVE-2025-0690 · GRUB2 (read command)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.