---
title: "CVE-2025-0686\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-0686?format=md
keywords: index, follow
---

# CVE-2025-0686

Publication date 18 February 2025

Last updated 11 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.4 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-0686?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in grub2. When performing a symlink lookup from a romfs
filesystem, grub's romfs filesystem module uses user-controlled parameters
from the filesystem geometry to determine the internal buffer size,
however, it improperly checks for integer overflows. A maliciously crafted
filesystem may lead some of those buffer size calculations to overflow,
causing it to perform a grub\_malloc() operation with a smaller size than
expected. As a result, the grub\_romfs\_read\_symlink() may cause
out-of-bounds writes when the calling grub\_disk\_read() function. This issue
may be leveraged to corrupt grub's internal critical data and can result in
arbitrary code execution by-passing secure boot protections.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-0686?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| grub2-unsigned | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| grub2-signed | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Ignored update incompatible with kernel |
| grub2 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Ignored update incompatible with kernel |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [eslerm](https://launchpad.net/~eslerm)

the grub2 package does not affect Ubuntu's Secure Boot
grub2-unsigned contains Secure Boot security fixes grub2 and
grub2-unsigned should have same major version Ubuntu Secure Boot
and ESM do not cover i386 trusty's GA kernel cannot handle new
versions of grub Note that key revocation is required to protect
against evil housekeeper attacks (such as BlackLotus)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.4 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Privileges required | High |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.4 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0686)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-0686)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-0686)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-0686)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-0686>
