CVE-2025-1118: Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabled
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.
Other sources
The grub's dump command is not blocked when grub is in lockdown mode. This allows the user to read any memory information, an attacker may leverage that in order to extract signatures, salts and other sensitive information from the memory.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1118?
The severity of CVE-2025-1118 is considered to be high due to the potential for sensitive information disclosure.
How do I fix CVE-2025-1118?
To fix CVE-2025-1118, update to the latest version of GNU GRUB 2 that addresses this vulnerability.
What systems are affected by CVE-2025-1118?
CVE-2025-1118 affects systems running GNU GRUB 2, particularly those utilizing lockdown mode.
What information can be accessed through CVE-2025-1118?
An attacker can use the dump command to access sensitive memory information, such as signatures and salts.
Is there a workaround for CVE-2025-1118?
As of now, the best approach is to apply patches provided by GNU or restrict access to the GRUB environment.