Heap Overflow Vulnerability in Grub2 Affects ReiserFS Filesystems
CVE-2025-0684
Key Information:
- Vendor
- CVE Published:
- 3 March 2025
What is CVE-2025-0684?
A vulnerability exists in Grub2 when executing symlink lookups on ReiserFS filesystems. This flaw allows user-controlled parameters to influence the internal buffer size calculation, risking integer overflows. A crafted filesystem could exploit this to cause buffer size calculations to overflow, initiating a grub_malloc() call with an insufficient size. Consequently, the grub_reiserfs_read_symlink() function may execute with an invalid length, which can lead to a heap-based out-of-bounds write and corruption of critical internal data. This vulnerability poses significant risks, including potential arbitrary code execution and circumvention of secure boot protections.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
