When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.
History

Wed, 05 Mar 2025 21:00:00 +0000

Type Values Removed Values Added
References

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
Title grub2: udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution Grub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References

Tue, 25 Feb 2025 02:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

Wed, 19 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title grub2: udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-03-03T14:17:32.517Z

Updated: 2025-03-05T20:43:36.299Z

Reserved: 2025-01-23T19:49:12.475Z

Link: CVE-2025-0689

cve-icon Vulnrichment

Updated: 2025-03-03T15:10:33.471Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-03T15:15:16.147

Modified: 2025-03-05T21:15:19.503

Link: CVE-2025-0689

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-18T18:00:00Z

Links: CVE-2025-0689 - Bugzilla