Grub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading data
Description
Integer overflow in GRUB2's squash4 filesystem module allows heap buffer overflow, potentially enabling arbitrary code execution and secure boot bypass.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer overflow in GRUB2's squash4 filesystem module allows heap buffer overflow, potentially enabling arbitrary code execution and secure boot bypass.
Vulnerability
A flaw exists in the squash4 filesystem module of GRUB2. When reading data from a squash4 filesystem, the module uses user-controlled parameters from the filesystem geometry to determine internal buffer sizes. It fails to properly check for integer overflows during these calculations. A maliciously crafted filesystem can cause a buffer size calculation to overflow, resulting in grub_malloc() allocating a smaller buffer than expected. Subsequently, direct_read() performs a heap-based out-of-bounds write when reading data. This affects GRUB2 versions that include the squash4 module; no specific version range is provided in the available references [1][2].
Exploitation
An attacker must be able to supply a specially crafted squash4 filesystem to the target system, for example via a bootable USB drive, CD-ROM, or network boot (PXE). No authentication is required if the attacker controls the boot media. The attacker crafts filesystem geometry values that trigger an integer overflow in the buffer size calculation. When GRUB attempts to read data from this filesystem, the overflow leads to a heap buffer overflow during the direct_read() operation. No user interaction beyond booting from the malicious filesystem is needed [1][2].
Impact
Successful exploitation allows the attacker to corrupt GRUB's internal critical data structures, potentially leading to arbitrary code execution within the GRUB environment. This code execution can bypass Secure Boot protections, as GRUB runs before the operating system and is trusted by the firmware. The attacker gains the ability to execute arbitrary code at the bootloader level, compromising the integrity and security of the entire boot chain [1][2].
Mitigation
As of the publication date (2025-03-03), no patched version of GRUB2 has been disclosed in the available references. Red Hat has acknowledged the issue but has not yet released a fix [1][2]. Until a patch is available, users should avoid using squash4 filesystems with GRUB when possible, or ensure that only trusted, unmodified filesystem images are used. This vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog at the time of writing.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
31- osv-coords29 versionspkg:rpm/opensuse/grub2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/grub2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/grub2&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Micro%206.1pkg:rpm/suse/grub2&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/grub2&distro=SUSE%20Manager%20Proxy%20Module%204.3pkg:rpm/suse/grub2&distro=SUSE%20Manager%20Server%204.3pkg:rpm/suse/grub2&distro=SUSE%20Manager%20Server%20Module%204.3
< 2.12-150600.8.18.2+ 28 more
- (no CPE)range: < 2.12-150600.8.18.2
- (no CPE)range: < 2.12-35.1
- (no CPE)range: < 2.04-150300.22.52.3
- (no CPE)range: < 2.04-150300.22.52.3
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150500.29.43.2
- (no CPE)range: < 2.06-150500.29.43.2
- (no CPE)range: < 2.04-150300.3.11.1
- (no CPE)range: < 2.04-150300.22.52.3
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150500.29.43.2
- (no CPE)range: < 2.12-150600.8.18.2
- (no CPE)range: < 2.12-150600.8.18.2
- (no CPE)range: < 2.02-181.2
- (no CPE)range: < 2.04-150300.22.52.3
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150500.29.43.2
- (no CPE)range: < 2.04-150300.22.52.3
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150500.29.43.2
- (no CPE)range: < 2.02-181.2
- (no CPE)range: < 2.12~rc1-6.1
- (no CPE)range: < 2.12-slfo.1.1_2.1
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150400.11.55.2
- (no CPE)range: < 2.06-150400.11.55.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- access.redhat.com/security/cve/CVE-2025-0678mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
News mentions
0No linked articles in our index yet.