
Technical analysis of CVE-2025-0690: integer overflow in GRUB2's read command leading to heap out-of-bounds write, arbitrary code execution, and Secure Boot bypass. Includes root cause, CVSS metrics, and vendor patch guidance.
CVE-2025-0690 is a critical integer overflow vulnerability in the GRUB2 boot loader, allowing arbitrary code execution and Secure Boot bypass. This flaw affects systems that rely on GRUB2 for secure boot, exposing the system before the operating system starts.
read (used to receive keyboard input).| Metric | Value | Description |
|---|---|---|
| Base Score | 6.1 (Moderate) | According to CISA-ADP and Red Hat. |
| Attack Vector | Physical (AV:P) | Requires physical or local access. |
| Complexity | Low (AC:L) | Easy to exploit with controlled input. |
| Privileges Required | High (PR:H) | Requires prior access to the system. |
| User Interaction | Required (UI:R) | The attacker must interact with the system. |
Several vendors have released patches to fix this vulnerability:
| Distribution/Vendor | Fixed Version | Reference |
|---|---|---|
| Red Hat | grub2-2.06-104.el9_6+ | RHSA-2025:6990 |
| Debian | grub2-2.12-6 (unstable) | Security Bug Tracker |
| Oracle Linux | Errata ELSA-2025-6990 | - |
| Dell | Updates on products such as PowerProtect and VxRail | - |
sudo dnf update grub2 grub2-common grub2-efi # RHEL/Fedora
sudo apt upgrade grub2 grub2-common grub2-efi # Debian/Ubuntu
grub-install --version
Kaleth Pwned!!