THREAT OPS › Threat News › [NVD] CVE-2025-0624 (HIGH 7.6) — A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environm
[NVD] CVE-2025-0624 (HIGH 7.6) — A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environm
CVE-2025-0624 CVSS: 7.6 HIGH Published: 2025-02-19T19:15:15.120
A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer
Indicators of compromise
- CVE-2025-0624cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-0624