MEDIUM
RefindPlusRepo RefindPlus BootLog.c GetDebugLogFile null pointer dereference
Published Apr 28, 2025
6.8
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue is the function GetDebugLogFile of the file Library/MemLogLib/BootLog.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The patch is identified as d2143a1e2deefddd9b105fb7160763c4f8d47ea2. It is recommended to apply a patch to fix this issue.
Affected products
-
- Version 0.14.2.ABStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| RefindPlusRepo | RefindPlus | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/RefindPlusRepo/RefindPlus/commit/d2143a1e2deefddd9b105fb7160763c4f8d47ea2 patch
- https://github.com/RefindPlusRepo/RefindPlus/issues/204 issue-tracking
- https://github.com/RefindPlusRepo/RefindPlus/issues/204#issuecomment-2696817643 issue-tracking
- https://vuldb.com/?ctiid.306338 signaturepermissions-required
- https://vuldb.com/?id.306338 vdb-entrytechnical-description
- https://vuldb.com/?submit.558122 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/RefindPlusRepo/RefindPlus/commit/d2143a1e2deefddd9b105fb7160763c4f8d47ea2 | patch | |
| https://github.com/RefindPlusRepo/RefindPlus/issues/204 | issue-tracking | |
| https://github.com/RefindPlusRepo/RefindPlus/issues/204#issuecomment-2696817643 | issue-tracking | |
| https://vuldb.com/?ctiid.306338 | signaturepermissions-required | |
| https://vuldb.com/?id.306338 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.558122 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 28, 2025
Updated Apr 28, 2025
Reserved Apr 26, 2025
Link CVE-2025-4002
CISA Vulnrichment
Updated Apr 28, 2025