UBUNTU-CVE-2025-0624

Source
https://ubuntu.com/security/CVE-2025-0624
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-0624.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2025-0624
Related
Published
2025-02-18T18:00:00Z
Modified
2025-02-26T04:38:29Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.

References

Affected packages

Ubuntu:Pro:14.04:LTS / grub2

Package

Name
grub2
Purl
pkg:deb/ubuntu/grub2@2.02~beta2-9ubuntu1.21?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.00-19ubuntu2
2.00-19ubuntu3
2.00-19ubuntu4
2.00-20
2.00-21
2.00-22
2.02~beta2-5
2.02~beta2-6
2.02~beta2-7
2.02~beta2-8
2.02~beta2-9
2.02~beta2-9ubuntu1
2.02~beta2-9ubuntu1.1
2.02~beta2-9ubuntu1.2
2.02~beta2-9ubuntu1.3
2.02~beta2-9ubuntu1.4
2.02~beta2-9ubuntu1.5
2.02~beta2-9ubuntu1.6
2.02~beta2-9ubuntu1.7
2.02~beta2-9ubuntu1.8
2.02~beta2-9ubuntu1.11
2.02~beta2-9ubuntu1.12
2.02~beta2-9ubuntu1.14
2.02~beta2-9ubuntu1.15
2.02~beta2-9ubuntu1.16
2.02~beta2-9ubuntu1.17
2.02~beta2-9ubuntu1.20
2.02~beta2-9ubuntu1.21

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:14.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.34.24?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.22
1.23
1.24
1.25
1.26
1.27
1.30
1.31
1.32
1.33
1.34
1.34.1
1.34.2
1.34.3
1.34.4
1.34.5
1.34.6
1.34.7
1.34.8
1.34.9
1.34.13
1.34.14
1.34.16
1.34.17
1.34.18
1.34.20
1.34.22
1.34.24

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.167~16.04.6?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.55
1.56
1.57
1.58
1.59
1.61
1.62
1.63
1.64
1.65
1.66
1.66.1
1.66.2
1.66.6
1.66.7
1.66.8
1.66.9
1.66.11
1.66.12
1.66.14
1.66.15
1.66.16
1.66.17
1.66.18
1.66.19
1.66.20
1.66.21
1.66.22
1.66.23
1.66.26
1.66.27
1.66.28
1.66.29
1.167~16.04.1
1.167~16.04.2
1.167~16.04.4
1.167~16.04.6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned@2.04-1ubuntu44.1.2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.04-1ubuntu44
2.04-1ubuntu44.1
2.04-1ubuntu44.1.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.187.3~18.04.1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.85
1.86
1.87
1.89
1.91
1.92
1.93
1.93.1
1.93.2
1.93.3
1.93.4
1.93.5
1.93.7
1.93.8
1.93.10
1.93.11
1.93.13
1.93.14
1.93.15
1.93.16
1.93.18
1.93.19
1.93.20
1.93.21
1.93.22
1.93.24
1.167~18.04.1
1.167~18.04.3
1.167~18.04.5
1.173.2~18.04.1
1.187.2~18.04.1
1.187.3~18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned@2.06-2ubuntu14.1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.04-1ubuntu44
2.04-1ubuntu44.1
2.04-1ubuntu44.1.2
2.04-1ubuntu47.4
2.06-2ubuntu14
2.06-2ubuntu14.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.187.6~20.04.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.128
1.129
1.130
1.131
1.133
1.134
1.135
1.136
1.137
1.138
1.139
1.140
1.141
1.142
1.142.1
1.142.3
1.142.4
1.142.5
1.142.6
1.142.8
1.142.9
1.142.10
1.142.11
1.167
1.167.2
1.173.2~20.04.1
1.173.4
1.187.2~20.04.2
1.187.3~20.04.1
1.187.4~20.04.1
1.187.6~20.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned@2.06-2ubuntu14.4?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.04-1ubuntu44
2.04-1ubuntu44.2
2.04-1ubuntu47.4
2.04-1ubuntu47.5
2.06-2ubuntu14
2.06-2ubuntu14.1
2.06-2ubuntu14.2
2.06-2ubuntu14.4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.187.6?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.173
1.174
1.176
1.177
1.178
1.179
1.180
1.182~22.04.1
1.187.2
1.187.3~22.04.1
1.187.4~22.04.1
1.187.6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned@2.06-2ubuntu14.4?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.04-1ubuntu47
2.04-1ubuntu48
2.06-2ubuntu3
2.06-2ubuntu4
2.06-2ubuntu5
2.06-2ubuntu6
2.06-2ubuntu7
2.06-2ubuntu10
2.06-2ubuntu14
2.06-2ubuntu14.1
2.06-2ubuntu14.2
2.06-2ubuntu14.4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.209.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.202
1.204
1.208
1.209
1.209.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned@2.12-5ubuntu5.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.12-1ubuntu7
2.12-1ubuntu9
2.12-5ubuntu4
2.12-5ubuntu5
2.12-5ubuntu5.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / grub2-signed

Package

Name
grub2-signed
Purl
pkg:deb/ubuntu/grub2-signed@1.202.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.197
1.199
1.201
1.202
1.202.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / grub2-unsigned

Package

Name
grub2-unsigned
Purl
pkg:deb/ubuntu/grub2-unsigned@2.12-1ubuntu7.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.12~rc1-10ubuntu4
2.12~rc1-12ubuntu2
2.12-1ubuntu1
2.12-1ubuntu7
2.12-1ubuntu7.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}