CVE-2025-0690
published 2025-02-24CVE-2025-0690: The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to…
PriorityP426medium6.1CVSS 3.1
AVPACLPRHUIRSUCHIHAH
EPSS
0.70%
49.5th percentile
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to overflow leading to a out-of-bounds write in the heap based buffer. This flaw may be leveraged to corrupt grub's internal critical data and secure boot bypass is not discarded as consequence.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.12-6 (forky) | grub2 2.12-6 (forky) |
| gnu | grub2 | >= 0 < 2.12-6 | 2.12-6 |
| gnu | grub2 | >= 0 < 2.12-6 | 2.12-6 |
| msrc | azl3_ansible_2.15.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ansible_2.17.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-25_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ansible_2.14.12-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grub2_2.06-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grub2_2.06-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grub2: read: Integer overflow may lead to out-of-bounds write
vendor_redhat·2025-02-18·CVSS 6.1
CVE-2025-0690 [MEDIUM] CWE-787 grub2: read: Integer overflow may lead to out-of-bounds write
grub2: read: Integer overflow may lead to out-of-bounds write
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to overflow leading to a out-of-bounds write in the heap based buffer. This flaw may be leveraged to corrupt grub's internal critical data and secure boot bypass is not discarded as consequence.
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line bi
Microsoft
Grub2: read: integer overflow may lead to out-of-bounds write
vendor_msrc·2025-02-11·CVSS 6.1
CVE-2025-0690 [MEDIUM] CWE-787 Grub2: read: integer overflow may lead to out-of-bounds write
Grub2: read: integer overflow may lead to out-of-bounds write
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https
Debian
CVE-2025-0690: grub2 - The read command is used to read the keyboard input from the user, while reads i...
vendor_debian·2025·CVSS 6.1
CVE-2025-0690 [MEDIUM] CVE-2025-0690: grub2 - The read command is used to read the keyboard input from the user, while reads i...
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to overflow leading to a out-of-bounds write in the heap based buffer. This flaw may be leveraged to corrupt grub's internal critical data and secure boot bypass is not discarded as consequence.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.12-6)
sid: resolved (fixed in 2.12-6)
trixie: resolved (fixed in 2.12-6)
Microsoft
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
vendor_msrc·2024-02-13·CVSS 5.5
CVE-2024-0690 [MEDIUM] CWE-116 Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Marine
OSV
CVE-2025-0690: The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further us
osv·2025-02-24·CVSS 6.1
CVE-2025-0690 [MEDIUM] CVE-2025-0690: The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further us
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to overflow leading to a out-of-bounds write in the heap based buffer. This flaw may be leveraged to corrupt grub's internal critical data and secure boot bypass is not discarded as consequence.
GHSA
GHSA-9fg2-2f57-9p5h: The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further us
ghsa_unreviewed·2025-02-24
CVE-2025-0690 [MEDIUM] CWE-787 GHSA-9fg2-2f57-9p5h: The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further us
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enough it's possible to make this variable to overflow leading to a out-of-bounds write in the heap based buffer. This flaw may be leveraged to corrupt grub's internal critical data and secure boot bypass is not discarded as consequence.
No detection rules found.
No public exploits indexed.
2025-02-24
Published