CVE-2025-0622
published 2025-02-18CVE-2025-0622: A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an…
PriorityP434medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.28%
19.8th percentile
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.12-6 (forky) | grub2 2.12-6 (forky) |
| gnu | grub2 | >= 0 < 2.12-6 | 2.12-6 |
| gnu | grub2 | >= 0 < 2.12-6 | 2.12-6 |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjmw-pmxv-8c6w: A flaw was found in command/gpg
ghsa_unreviewed·2025-02-18
CVE-2025-0622 [MEDIUM] CWE-416 GHSA-vjmw-pmxv-8c6w: A flaw was found in command/gpg
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.
OSV
CVE-2025-0622: A flaw was found in command/gpg
osv·2025-02-18·CVSS 6.4
CVE-2025-0622 [MEDIUM] CVE-2025-0622: A flaw was found in command/gpg
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.
Red Hat
screen: Screen by Default Creates World Writable PTYs
vendor_redhat·2025-05-13·CVSS 5.1
CVE-2025-46803 [MEDIUM] CWE-282 screen: Screen by Default Creates World Writable PTYs
screen: Screen by Default Creates World Writable PTYs
The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.
A flaw was found in Screen. The default mode for pseudo-terminals (PTYs) allocated by Screen was changed from 0620 to 0622. This vulnerability allows public writes to any PTYs in the system.
Statement: The change in the default PTY mode from 0620 to 0622 in Screen represents a significant security vulnerability because it directly exposes privileged terminal sessions to unauthorized local modification. In multi-user environments, PTYs act as communication endpoints between user shells and the system, and world-writable PTYs (0622) allow any user on the system to inject arbit
Red Hat
grub2: command/gpg: Use-after-free due to hooks not being removed on module unload
vendor_redhat·2025-02-18·CVSS 6.4
CVE-2025-0622 [MEDIUM] CWE-416 grub2: command/gpg: Use-after-free due to hooks not being removed on module unload
grub2: command/gpg: Use-after-free due to hooks not being removed on module unload
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-fr
Debian
CVE-2025-0622: grub2 - A flaw was found in command/gpg. In some scenarios, hooks created by loaded modu...
vendor_debian·2025·CVSS 6.4
CVE-2025-0622 [MEDIUM] CVE-2025-0622: grub2 - A flaw was found in command/gpg. In some scenarios, hooks created by loaded modu...
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.12-6)
sid: resolved (fixed in 2.12-6)
trixie: resolved (fixed in 2.12-6)
No detection rules found.
No public exploits indexed.
2025-02-18
Published