GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (UFS symlink handling): Integer overflow on symlink handling in UFS gives a heap out-of-bounds write and a path

CVE-2025-0677Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

Integer overflow on symlink handling in UFS gives a heap out-of-bounds write and a path to loading unsigned code with Secure Boot on.

Who can reach it

Attacker-supplied UFS filesystem image.

What to do

grub2 package update + reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.