CVE-2025-0624: Red Hat Enterprise Linux 10

High severity, CVSS 7.6. EPSS: 1.4% chance of exploitation in the next 30 days.

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 1:2.02-0.87.el7_9.15 (fixed in 1:2.02-0.87.el7_9.15)
  • Red Hat Red Hat Enterprise Linux 8: before 1:2.02-162.el8_10 (fixed in 1:2.02-162.el8_10)
  • Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 1:2.02-87.el8_2.13 (fixed in 1:2.02-87.el8_2.13)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 1:2.02-99.el8_4.12 (fixed in 1:2.02-99.el8_4.12)
  • Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service: before 1:2.02-99.el8_4.12 (fixed in 1:2.02-99.el8_4.12)
  • Red Hat Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions: before 1:2.02-99.el8_4.12 (fixed in 1:2.02-99.el8_4.12)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 1:2.02-123.el8_6.18 (fixed in 1:2.02-123.el8_6.18)
  • Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 1:2.02-123.el8_6.18 (fixed in 1:2.02-123.el8_6.18)
  • Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 1:2.02-123.el8_6.18 (fixed in 1:2.02-123.el8_6.18)
  • Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 1:2.02-152.el8_8.2 (fixed in 1:2.02-152.el8_8.2)
  • Red Hat Red Hat Enterprise Linux 9: before 1:2.06-94.el9_5 (fixed in 1:2.06-94.el9_5)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 1:2.06-27.el9_0.22 (fixed in 1:2.06-27.el9_0.22)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 1:2.06-61.el9_2.10 (fixed in 1:2.06-61.el9_2.10)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 1:2.06-86.el9_4.2 (fixed in 1:2.06-86.el9_4.2)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202503310142-0 (fixed in 412.86.202503310142-0)
  • Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202504070146-0 (fixed in 413.92.202504070146-0)
  • Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202505141057-0 (fixed in 414.92.202505141057-0)
  • Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202504282058-0 (fixed in 415.92.202504282058-0)
  • Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202503252048-0 (fixed in 416.94.202503252048-0)
  • Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202503241418-0 (fixed in 417.94.202503241418-0)
  • Red Hat Red Hat Openshift Container Platform 4.18: before 418.94.202504021150-0 (fixed in 418.94.202504021150-0)

Published 2025-02-19. Last modified 2026-08-31.