CVE-2025-0684: Grub2: reiserfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. A maliciouly crafted filesystem may lead some of those buffer size calculations to overflow, causing it to perform a grubmalloc() operation with a smaller size than expected. As a result, the grubreiserfsreadsymlink() will call grubreiserfsreadreal() with a overflown length parameter, leading to a heap based out-of-bounds write during data reading. This flaw may be leveraged to corrupt grub's internal critical data and can result in arbitrary code execution, by-passing secure boot protections.
Other sources
Grub2: reiserfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data
— Microsoft
When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffers size, however it misses to properly check for integer overflows. A maliciouly crafted filesystem may lead some of those buffer size calculation to overflow, causing it to perform a grubmalloc() operation with a smaller size than expected. As a result the grubreiserfsreadsymlink() will call grubreiserfsreadreal() with a overflown length parameter leading to a heap based out-of-bounds write during data reading. This flaw may be leveraged to corrupt grub's internal critical data and may result in arbitrary code execution by-passing secure boot protections.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.06-25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.06-15
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0684?
CVE-2025-0684 has a high severity rating due to its potential for exploitation through integer overflow vulnerabilities.
How do I fix CVE-2025-0684?
Fixing CVE-2025-0684 involves updating the GRUB package to the latest version provided by your operating system vendor.
What systems are affected by CVE-2025-0684?
CVE-2025-0684 affects systems using the GRUB bootloader that employ a reiserfs filesystem.
What types of attacks can CVE-2025-0684 enable?
CVE-2025-0684 can enable attackers to perform arbitrary code execution due to its integer overflow vulnerability.
Is there a workaround for CVE-2025-0684 if I cannot apply a patch right away?
A potential workaround for CVE-2025-0684 is to avoid using reiserfs filesystems until the vulnerability is mitigated.