GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (dump command lockdown): The dump command was not disabled under Secure Boot lockdown, letting a privileged user

CVE-2025-1118Firmware, BMC & network fabricGRUB2 2025 batchcurated

Impact

The dump command was not disabled under Secure Boot lockdown, letting a privileged user read arbitrary memory at boot. That includes anything the firmware left in RAM - most usefully, key material and Secure Boot state. Low CVSS, high value as a reconnaissance primitive before a real bypass.

Who can reach it

Local privileged user at the GRUB shell.

What to do

grub2 package update + reboot. A GRUB password limits access to the shell in the meantime, but does not fix the lockdown gap.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.