PT-2025-7491 · Grub2+5 · Grub2+5

Published

2025-02-18

·

Updated

2025-10-17

·

CVE-2025-1118

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grub2 (affected versions not specified)
Description A flaw was found in Grub2, where the dump command is not blocked when Grub is in lockdown mode. This allows a user to read any memory information, and an attacker may leverage this to extract signatures, salts, and other sensitive information from the memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALSA-2025:16154
ALT-PU-2025-5587
ALT-PU-2025-6088
AZL-56904
AZL-57025
BDU:2025-11727
CVE-2025-1118
OESA-2025-1216
OESA-2025-1217
OESA-2025-1218
OESA-2025-1291
OESA-2025-1292
OPENSUSE-SU-2025:14822-1
OPENSUSE-SU-2025_0586-1
OPENSUSE-SU-2025_0587-1
OPENSUSE-SU-2025_0588-1
OPENSUSE-SU-2025_0607-1
RHSA-2025:16154
SUSE-SU-2025:01961-1
SUSE-SU-2025:0586-1
SUSE-SU-2025:0587-1
SUSE-SU-2025:0588-1
SUSE-SU-2025:0607-1
SUSE-SU-2025:0629-1
SUSE-SU-2025:20511-1
SUSE-SU-2025:20863-1
SUSE-SU-2025_0586-1
SUSE-SU-2025_0587-1
SUSE-SU-2025_0588-1
SUSE-SU-2025_0607-1
SUSE-SU-2025_0629-1

Affected Products

Alt Linux
Astra Linux
Debian
Grub2
Red Os
Suse