📦 Grub2

by Gnu

🔍 What is Grub2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-61662

HIGH CVSS 7.8 Nov 18, 2025

A use-after-free vulnerability in GRUB's gettext module allows attackers to invoke an orphaned command after module unloading, causing memory access to invalid locations. This can lead to GRUB crashes...

CVE-2025-0678

HIGH CVSS 7.8 Mar 3, 2025

A heap-based buffer overflow vulnerability in grub2's squash4 filesystem module allows attackers to execute arbitrary code by crafting malicious filesystems. This affects systems using grub2 with squa...

CVE-2024-45782

HIGH CVSS 7.8 Mar 3, 2025

This vulnerability in the HFS filesystem driver allows attackers to trigger a heap-based buffer overflow by providing a specially crafted volume name. This could lead to arbitrary code execution in GR...

CVE-2025-1125

HIGH CVSS 7.8 Mar 3, 2025

This vulnerability in GRUB's HFS filesystem module allows integer overflow when calculating buffer sizes from malicious filesystem metadata. Attackers can exploit this to write past allocated buffers,...

CVE-2024-56737

HIGH CVSS 8.8 Dec 29, 2024

CVE-2024-56737 is a heap-based buffer overflow vulnerability in GNU GRUB2's HFS filesystem parser. Attackers can exploit this by providing specially crafted HFS filesystem data to execute arbitrary co...

CVE-2023-4692

HIGH CVSS 7.5 Oct 25, 2023

An out-of-bounds write vulnerability in grub2's NTFS filesystem driver allows attackers to corrupt heap metadata by presenting a specially crafted NTFS filesystem image. This can lead to arbitrary cod...

CVE-2022-28733

HIGH CVSS 8.1 Jul 20, 2023

CVE-2022-28733 is an integer underflow vulnerability in GRUB2's network stack that allows remote attackers to cause buffer overflow via specially crafted IP packets. This affects systems using GRUB2 w...

CVE-2021-3697

HIGH CVSS 7.0 Jul 6, 2022

CVE-2021-3697 is a heap buffer underflow vulnerability in GRUB2's JPEG parser that allows a crafted JPEG image to corrupt heap memory. Successful exploitation could lead to arbitrary code execution or...

CVE-2021-20233

HIGH CVSS 8.2 Mar 3, 2021

This GRUB2 vulnerability allows attackers to corrupt memory by one byte for each quote in menu input due to an incorrect length calculation. It affects systems using GRUB2 versions prior to 2.06, pote...

CVE-2020-27779

HIGH CVSS 7.5 Mar 3, 2021

This vulnerability in GRUB2 allows privileged attackers to bypass Secure Boot protections by using the cutmem command to remove memory address ranges. This could enable loading of unauthorized code or...

CVE-2020-25632

HIGH CVSS 8.2 Mar 3, 2021

This CVE-2020-25632 vulnerability in GRUB2 allows attackers to unload kernel modules that other modules depend on, creating a use-after-free condition that can lead to arbitrary code execution. It aff...

CVE-2025-0685

MEDIUM CVSS 6.4 Mar 3, 2025

This CVE describes an integer overflow vulnerability in grub2's JFS filesystem module that allows buffer overflow when reading maliciously crafted filesystems. Attackers can exploit this to execute ar...

CVE-2024-45778

MEDIUM CVSS 4.1 Mar 3, 2025

A stack overflow vulnerability in GRUB2's BFS filesystem parser allows an attacker to crash the bootloader by providing a specially crafted BFS filesystem. This affects systems using GRUB2 with BFS su...

CVE-2024-45780

MEDIUM CVSS 6.7 Mar 3, 2025

CVE-2024-45780 is a heap buffer overflow vulnerability in grub2's tar file parser that allows integer overflow during filename buffer allocation. Attackers can exploit this with a crafted tar file to ...

CVE-2024-45777

MEDIUM CVSS 6.7 Feb 19, 2025

This vulnerability in grub2 allows attackers to trigger an out-of-bounds write when processing language files, potentially overwriting sensitive heap data. This could lead to bypassing secure boot pro...