CVE-2025-0622 Details
Description
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.
A use-after-free vulnerability has been identified in the Grub2 bootloader, specifically within the command/gpg module. This issue arises because hooks created by loaded modules are not always removed when the module is unloaded. An attacker can exploit this flaw by forcing Grub2 to execute the hooks after the corresponding module has been unloaded, leading to a use-after-free condition. If successfully exploited, this vulnerability could allow arbitrary code execution, potentially enabling the attacker to bypass secure boot protections. This vulnerability affects Red Hat Enterprise Linux 9 and is present in the Grub2 package.
Users can apply the available update for Grub2 in Red Hat Enterprise Linux 9, as detailed in the Red Hat Security Advisory RHSA-2025:6990.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 18, 2025CISA-ADP
Assessed Feb 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:16154 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2025:6990 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/security/cve/CVE-2025-0622 | [email protected] | AdvisoryVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2345865 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat Enterprise Linux | >= 9, < 9.6 |
CPE
Remediation
| |
| Red Hat Enterprise Linux Server | >= 9.6 |
CPE
Remediation
| |
| Red Hat OpenShift Container Platform | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 24, 2026 | CVE Modified | [email protected] |
| Sep 18, 2025 | CVE Modified | [email protected] |
| May 13, 2025 | CVE Modified | [email protected] |
| Feb 18, 2025 | New CVE Received | [email protected] |
Volerion