Wind River Support Network

HomeDefectsLIN1021-13507
Fixed

LIN1021-13507 : Security Advisory - grub - CVE-2025-0622

Created: Feb 18, 2025    Updated: May 26, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

CREATE(Triage):(User=admin) CVE-2025-0622 (https://nvd.nist.gov/vuln/detail/CVE-2025-0622)

CVEs


Live chat
Online