CVE-2025-0678 is a critical vulnerability in grub2, affecting products like GNU and Red Hat Enterprise Linux and OpenShift Container Platform. This flaw allows an attacker to craft a malicious squash4 filesystem that exploits integer overflows in grub's buffer size calculations, leading to a heap-based out-of-bounds write. This can corrupt critical grub data and potentially enable arbitrary code execution, bypassing secure boot protections. With a CVSS score of 7.8 (High), this vulnerability has a local attack vector with low complexity, requiring low privileges and no user interaction. The potential impact is high for confidentiality, integrity, and availability. While not currently in the KEV catalog or Hot List, and with no public exploit code available (Metasploit, Nuclei, ExploitDB), its potential for bypassing secure boot makes it a significant concern. Community discussion and media coverage are limited, with only one mention and one article, respectively, though the article highlights Microsoft's use of AI to find such bootloader flaws. Despite the lack of active exploitation, the severe potential impact warrants attention, particularly given the foundational role of grub2 in system security.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.12CPE matchmatch criteria | cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.