Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjmw-pmxv-8c6w

Опубликовано: 18 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

EPSS

Процентиль: 20%
0.00064
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 6.4
ubuntu
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

CVSS3: 6.4
redhat
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

CVSS3: 6.4
nvd
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

CVSS3: 6.4
debian
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by l ...

oracle-oval
3 месяца назад

ELSA-2025-6990: grub2 security update (MODERATE)

EPSS

Процентиль: 20%
0.00064
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-416