CVE-2025-1118

A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.
Configurations

No configuration.

History

18 Sep 2025, 09:15

Type Values Removed Values Added
Summary
  • (es) Se encontró un defecto en Grub2. El comando de volcado de Grub no se bloquea cuando GRUB está en modo de bloqueo, lo que permite al usuario leer cualquier información de memoria, y un atacante puede aprovechar esto para extraer firmas, sales y otra información confidencial de la memoria.
References
  • () https://access.redhat.com/errata/RHSA-2025:16154 -

19 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-19 18:15

Updated : 2025-09-18 09:15


NVD link : CVE-2025-1118

Mitre link : CVE-2025-1118

CVE.ORG link : CVE-2025-1118


JSON object : View

Products Affected

No product.

CWE
CWE-501

Trust Boundary Violation