cbcvebase.
CVE-2025-0622
published 2025-02-18

CVE-2025-0622: A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an…

PriorityP434medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.28%
19.8th percentile
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.

Affected

3 ranges
VendorProductVersion rangeFixed in
debiangrub2< grub2 2.12-6 (forky)grub2 2.12-6 (forky)
gnugrub2>= 0 < 2.12-62.12-6
gnugrub2>= 0 < 2.12-62.12-6

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.