A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.
History

Wed, 19 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.
Title grub2: net: Out-of-bounds write in grub_net_search_config_file() Grub2: net: out-of-bounds write in grub_net_search_config_file()
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References

Wed, 19 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title grub2: net: Out-of-bounds write in grub_net_search_config_file()
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-19T18:39:29.836Z

Reserved: 2025-01-21T16:49:51.381Z

Link: CVE-2025-0624

cve-icon Vulnrichment

Updated: 2025-02-19T18:39:24.255Z

cve-icon NVD

Status : Received

Published: 2025-02-19T19:15:15.120

Modified: 2025-02-19T19:15:15.120

Link: CVE-2025-0624

cve-icon Redhat

Severity : Important

Publid Date: 2025-02-18T18:00:00Z

Links: CVE-2025-0624 - Bugzilla