RHSA-2025:16154MediumCVSS 6.7

Red Hat Security Advisory: grub2 security update

Published
September 18, 2025
Last Modified
June 30, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-45776 — grub2: grub-core/gettext: Integer overflow leads to Heap OOB Write and Read. CVE-2024-45781 — grub2: fs/ufs: OOB write in the heap CVE-2025-0622 — grub2: command/gpg: Use-after-free due to hooks not being removed on module unload CVE-2025-0677 — grub2: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks CVE-2025-1118 — grub2: commands/dump: The dump command is not in lockdown when secure boot is enabled

🔗 References (10)