When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap Out-of-bounds write, causing data integrity issues and eventually allowing an attacker to circumvent secure boot protections.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:6990 https://access.redhat.com/errata/RHSA-2025:6990