CVE-2025-0678General(gnu / enterprise_linux)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciously crafted filesystem may lead some of those buffer size calculations to overflow, causing it to perform a grub_malloc() operation with a smaller size than expected. As a result, the direct_read() will perform a heap based out-of-bounds write during data reading. This flaw may be leveraged to corrupt grub's internal critical data and may result in arbitrary code execution, by-passing secure boot protections.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • grub2
  • openshift_container_platform

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
enterprise_linuxgrub2openshift_container_platform

4 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 103-26
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • procles@vcprocles
    General

    @katanga_uranium @DoingFedTime 1. I think it's impossible right now to install Ubuntu with encrypted /boot, afaik the installer requires it to be unencrypted 2. CVE-2021-3695,3696,3697 — images CVE-2025-0678 (this one will be left afaik cuz kernel+gadget snap system kek) CVE-2025-1125,0684 etc. — filesystems

    Post summary

    The tweet simply enumerates CVE identifiers without providing evidence of exploitation, PoC, patches, or technical details.

    00010215
    43 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appgnugrub2---
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhatopenshift_container_platform4.0--

Explore more