U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-0677

Change History

New CVE Received from Red Hat, Inc. 2/19/2025 2:15:15 PM

Action Type Old Value New Value
Added Description

								
							
							
						
A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. When this occurs, grub_malloc() may be called with a smaller value than needed. When further reading the data from the disk into the buffer, the grub_ufs_lookup_symlink() function will write past the end of the allocated size. An attack can leverage this by crafting a malicious filesystem, and as a result, it will corrupt data stored in the heap, allowing for arbitrary code execution used to by-pass secure boot mechanisms.
Added CVSS V3.1

								
							
							
						
AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-787
Added Reference

								
							
							
						
https://access.redhat.com/security/cve/CVE-2025-0677
Added Reference

								
							
							
						
https://bugzilla.redhat.com/show_bug.cgi?id=2346116