Wind River Support Network

HomeDefectsLIN1021-13513
Fixed

LIN1021-13513 : Security Advisory - grub - CVE-2025-0689

Created: Feb 18, 2025    Updated: May 26, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

https://nvd.nist.gov/vuln/detail/CVE-2025-0689

CVEs


Live chat
Online