RHSA-2025:3396: Important: grub2 security update
Important: grub2 security update
Other sources
The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.Security Fix(es): grub2: net: Out-of-bounds write in grubnetsearchconfigfile() (CVE-2025-0624) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3396?
The severity of RHSA-2025:3396 is classified as important.
How do I fix RHSA-2025:3396?
To fix RHSA-2025:3396, update the grub2 packages to version 2.02-0.87.el7_9.15.
What systems are affected by RHSA-2025:3396?
RHSA-2025:3396 affects Red Hat Enterprise Linux Server and its extended life cycle support versions across various architectures.
Is there a workaround for RHSA-2025:3396?
There is no official workaround for RHSA-2025:3396; updating the affected packages is recommended.
What components are included in the RHSA-2025:3396 update?
The RHSA-2025:3396 update includes several components such as grub2, grub2-common, and grub2-tools, among others.