Executive Summary

Informations
Name CVE-2025-0624 First vendor Publication 2025-02-19
Vendor Cve Last vendor Modification 2025-05-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0624

Sources (Detail)

https://access.redhat.com/errata/RHSA-2025:2521
https://access.redhat.com/errata/RHSA-2025:2653
https://access.redhat.com/errata/RHSA-2025:2655
https://access.redhat.com/errata/RHSA-2025:2675
https://access.redhat.com/errata/RHSA-2025:2784
https://access.redhat.com/errata/RHSA-2025:2799
https://access.redhat.com/errata/RHSA-2025:2867
https://access.redhat.com/errata/RHSA-2025:2869
https://access.redhat.com/errata/RHSA-2025:3297
https://access.redhat.com/errata/RHSA-2025:3301
https://access.redhat.com/errata/RHSA-2025:3367
https://access.redhat.com/errata/RHSA-2025:3396
https://access.redhat.com/errata/RHSA-2025:3573
https://access.redhat.com/errata/RHSA-2025:3577
https://access.redhat.com/errata/RHSA-2025:3780
https://access.redhat.com/errata/RHSA-2025:4422
https://access.redhat.com/errata/RHSA-2025:7702
https://access.redhat.com/security/cve/CVE-2025-0624
https://bugzilla.redhat.com/show_bug.cgi?id=2346112
https://security.netapp.com/advisory/ntap-20250516-0006/
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
Date Informations
2025-05-26 21:20:58
  • Multiple Updates
2025-03-31 09:20:46
  • Multiple Updates
2025-03-28 09:20:50
  • Multiple Updates
2025-03-17 13:20:50
  • Multiple Updates
2025-03-17 09:20:51
  • Multiple Updates
2025-03-13 21:21:22
  • Multiple Updates
2025-03-13 17:21:16
  • Multiple Updates
2025-03-12 13:20:59
  • Multiple Updates
2025-03-11 17:20:48
  • Multiple Updates
2025-03-11 13:20:52
  • Multiple Updates
2025-03-10 21:20:43
  • Multiple Updates
2025-02-20 00:20:27
  • First insertion