Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-0622

Опубликовано: 18 фев. 2025
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

EPSS

Процентиль: 18%
0.00058
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 6.4
ubuntu
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

CVSS3: 6.4
redhat
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

CVSS3: 6.4
debian
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by l ...

CVSS3: 6.4
github
6 месяцев назад

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

oracle-oval
3 месяца назад

ELSA-2025-6990: grub2 security update (MODERATE)

EPSS

Процентиль: 18%
0.00058
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-416