<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:28:39.830266+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:16154</id>
    <title>ALSA-2025:16154 — Moderate: grub2 security update</title>
    <updated>2026-10-02T23:28:40.253141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: grub2-common, AlmaLinux:10: grub2-efi-aa64-modules, AlmaLinux:10: grub2-efi-x64-modules, AlmaLinux:10: grub2-pc-modules, AlmaLinux:10: grub2-ppc64le-modules</p>
<p>The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.</p>
<p>Security Fix(es):</p>
<p>* grub2: grub-core/gettext: Integer overflow leads to Heap OOB Write and Read. (CVE-2024-45776)
  * grub2: fs/ufs: OOB write in the heap (CVE-2024-45781)
  * grub2: command/gpg: Use-after-free due to hooks not being removed on module unload (CVE-2025-0622)
  * grub2: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks (CVE-2025-0677)
  * grub2: commands/dump: The dump command is not in lockdown when secure boot is enabled (CVE-2025-1118)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:16154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07124</id>
    <title>bdu:2025-07124</title>
    <updated>2026-10-02T23:28:40.253228+00:00</updated>
    <content>bdu:2025-07124</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-0677</id>
    <title>BELL-CVE-2025-0677</title>
    <updated>2026-10-02T23:28:40.253247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: grub, Alpaquita:stream: grub</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-0677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</id>
    <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T23:28:40.253267+00:00</updated>
    <content>certfr-2026-avi-0316</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-19252</id>
    <title>cnvd-2025-19252</title>
    <updated>2026-10-02T23:28:40.253284+00:00</updated>
    <content>cnvd-2025-19252</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-19252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331222</id>
    <title>EUVD-2026-331222</title>
    <updated>2026-10-02T23:28:40.253295+00:00</updated>
    <content>EUVD-2026-331222</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-0677</id>
    <title>fkie_cve-2025-0677</title>
    <updated>2026-10-02T23:28:40.253305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. When this occurs, grub_malloc() may be called with a smaller value than needed. When further reading the data from the disk into the buffer, the grub_ufs_lookup_symlink() function will write past the end of the allocated size. An attack can leverage this by crafting a malicious filesystem, and as a result, it will corrupt data stored in the heap, allowing for arbitrary code execution used to by-pass secure boot mechanisms.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-0677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h592-gmp8-rvr7</id>
    <title>GHSA-h592-gmp8-rvr7</title>
    <updated>2026-10-02T23:28:40.253330+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. When this occurs, grub_malloc() may be called with a smaller value than needed. When further reading the data from the disk into the buffer, the grub_ufs_lookup_symlink() function will write past the end of the allocated size. An attack can leverage this by crafting a malicious filesystem, and as a result, it will corrupt data stored in the heap, allowing for arbitrary code execution used to by-pass secure boot mechanisms.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h592-gmp8-rvr7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-0677</id>
    <title>msrc_CVE-2025-0677 — Grub2: ufs: integer overflow may lead to heap based out-of-bounds write when handling symlinks</title>
    <updated>2026-10-02T23:28:40.253348+00:00</updated>
    <content>msrc_CVE-2025-0677</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-0677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1216</id>
    <title>OESA-2025-1216 — grub2 security update</title>
    <updated>2026-10-02T23:28:40.253364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: grub2</p>
<p>GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.

Security Fix(es):</p>
<p>A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive information to bypass secure boot protections is not discarded.(CVE-2024-45774)</p>
<p>A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub&amp;apos;s argument list. However, it fails to check in case the memory allocation fails. Once the allocation fails, a NULL point will be processed by the parse_option() function, leading grub to crash or, in some rare scenarios, corrupt the IVT data.(CVE-2024-45775)</p>
<p>When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes. This flaw allows an attacker to leak sensitive data or overwrite critical data, possibly circumventing secure boot protections.(CVE-2024-45776)</p>
<p>A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14822-1</id>
    <title>openSUSE-SU-2025:14822-1 — grub2-2.12-35.1 on GA media</title>
    <updated>2026-10-02T23:28:40.253431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2-2.12-35.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14822-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:16154</id>
    <title>RHSA-2025:16154 — Red Hat Security Advisory: grub2 security update</title>
    <updated>2026-10-02T23:28:40.253458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2: grub-core/gettext: Integer overflow leads to Heap OOB Write and Read. grub2: fs/ufs: OOB write in the heap grub2: command/gpg: Use-after-free due to hooks not being removed on module unload grub2: UFS: Integer overflow may lead to heap based out-of-bounds write when handling symlinks grub2: commands/dump: The dump command is not in lockdown when secure boot is enabled</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:16154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01961-1</id>
    <title>SUSE-SU-2025:01961-1 — Security update for grub2</title>
    <updated>2026-10-02T23:28:40.253481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01961-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-0677</id>
    <title>UBUNTU-CVE-2025-0677</title>
    <updated>2026-10-02T23:28:40.253507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: grub2, Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-signed, Ubuntu:16.04:LTS: grub2-unsigned, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned, Ubuntu:22.04:LTS: grub2-signed, Ubuntu:22.04:LTS: grub2-unsigned and 6 more</p>
<p>A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. When this occurs, grub_malloc() may be called with a smaller value than needed. When further reading the data from the disk into the buffer, the grub_ufs_lookup_symlink() function will write past the end of the allocated size. An attack can leverage this by crafting a malicious filesystem, and as a result, it will corrupt data stored in the heap, allowing for arbitrary code execution used to by-pass secure boot mechanisms.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-0677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0396</id>
    <title>WID-SEC-W-2025-0396 — Grub: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:28:40.253549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Grub ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben oder nicht spezifizierte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0396"/>
  </entry>
</feed>
