Database/Firmware, BMC & network fabric
GRUB2 (squashfs): Integer overflow in the squash4 filesystem module leading to out-of-bounds write and possible Secure
CVSS 7.8CVE-2025-0678Firmware, BMC & network fabriccurated
Impact
Integer overflow in the squash4 filesystem module leading to out-of-bounds write and possible Secure Boot bypass
Who can reach it
Local, crafted filesystem image
What to do
GRUB2 update plus dbx revocation; squashfs is used by live/netboot images, so this lands directly on the bare-metal provisioning path
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/steering/hws): A matcher that fails to disconnect is reinsertedCVE-2025-21751 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/steering/hws)High
- Linux kernel mlx5_core eswitch vport QoS scheduling: When enabling per-vport QoS fails, the scheduling node is leakedCVE-2025-21882 · Linux kernel mlx5_core eswitch vport QoS schedulingHigh
- Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodes: The AMD microcode loader iterated every NUMA nodeCVE-2025-21991 · Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodesHigh
- Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces): RDMA hardware counter sysfs attributesCVE-2025-22089 · Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces)High
- Dell SmartFabric OS10 (command injection with elevated privileges): Local low-privilege attacker executes commandsCVE-2025-22472 · Dell SmartFabric OS10 (command injection with elevated privileges)High
- Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switchCVE-2025-22473 · Dell SmartFabric OS10 (command injection, local)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.