RHSA-2025:16154MediumCVSS 6.7
Red Hat Security Advisory: grub2 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-45776 — grub2: grub-core/gettext: Integer overflow leads to Heap OOB Write and Read. CVE-2024-45781 — grub2: fs/ufs: OOB write in the heap CVE-2025-0622 — grub2: command/gpg: Use-after-free due to hooks not being removed on module unload CVE-2025-0677 — grub2: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks CVE-2025-1118 — grub2: commands/dump: The dump command is not in lockdown when secure boot is enabled
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2025:16154
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2339182
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2345865
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346137
- externalhttps://issues.redhat.com/browse/RHEL-98679
- externalhttps://issues.redhat.com/browse/RHEL-98682
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16154.json