Логотип exploitDog
bind:"BDU:2025-07125" OR bind:"CVE-2025-0689"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-07125" OR bind:"CVE-2025-0689"

Количество 11

Количество 11

fstec логотип

BDU:2025-07125

7 месяцев назад

Уязвимость функции grub_udf_read_block загрузчика операционных систем Grub2, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2025-0689

6 месяцев назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2025-0689

7 месяцев назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2025-0689

6 месяцев назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2025-0689

6 месяцев назад

When reading data from disk, the grub's UDF filesystem module utilizes ...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-q7w8-q2f9-vcmh

6 месяцев назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0629-1

7 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0607-1

7 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0588-1

7 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0587-1

7 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0586-1

7 месяцев назад

Security update for grub2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-07125

Уязвимость функции grub_udf_read_block загрузчика операционных систем Grub2, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes ...

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-q7w8-q2f9-vcmh

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0629-1

Security update for grub2

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0607-1

Security update for grub2

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0588-1

Security update for grub2

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0587-1

Security update for grub2

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0586-1

Security update for grub2

7 месяцев назад

Уязвимостей на страницу