Bug 2345865 (CVE-2025-0622) - CVE-2025-0622 grub2: command/gpg: Use-after-free due to hooks not being removed on module unload
Summary: CVE-2025-0622 grub2: command/gpg: Use-after-free due to hooks not being remov...
Keywords:
Status: NEW
Alias: CVE-2025-0622
Deadline: 2025-02-18
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-02-14 22:21 UTC by OSIDB Bzimport
Modified: 2025-05-13 08:41 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:6990 0 None None None 2025-05-13 08:41:25 UTC

Description OSIDB Bzimport 2025-02-14 22:21:36 UTC
In some scenarios hooks created by loaded modules are not being removed when the related module is being unloaded. An attacker may leverage this by forcing the grub2 to call the hooks once the module which registered it was unloaded, leading to a Use-after-free vulnerability. If correctly exploited this vulnerability may result in Arbitrary Code Execution eventually allowing the attacker to by-pass secure boot protections.

Comment 2 errata-xmlrpc 2025-05-13 08:41:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:6990 https://access.redhat.com/errata/RHSA-2025:6990


Note You need to log in before you can comment on or make changes to this bug.