Search CVE reports
1 – 10 of 57 results
CVE-2025-4382
Medium priorityA flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-1125
Medium priorityWhen reading data from a hfs filesystem, grub’s hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows....
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-1118
Medium priorityA flaw was found in grub2. Grub’s dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0690
Medium priorityThe read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0689
Medium priorityWhen reading data from disk, the grub’s UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0686
Medium priorityA flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub’s romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0685
Medium priorityA flaw was found in grub2. When reading data from a jfs filesystem, grub’s jfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0684
Medium priorityA flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub’s reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however,...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0678
Medium priorityA flaw was found in grub2. When reading data from a squash4 filesystem, grub’s squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2025-0677
Medium priorityA flaw was found in grub2. When performing a symlink lookup, the grub’s UFS module checks the inode’s data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size...
3 affected packages
grub2, grub2-signed, grub2-unsigned
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
grub2 | Not affected | Not affected | Not affected | Not affected |
grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |