GNU / Grub2
54 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-97876 | Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address | MEDIUM | 6.4 | Oct 2, 2026 |
| CVE-2025-54770 | Grub2: use-after-free in net_set_vlan | MEDIUM | 4.9 | Nov 18, 2025 |
| CVE-2025-61664 | Grub2: missing unregister call for normal_exit command may lead to use-after-free | MEDIUM | 4.9 | Nov 18, 2025 |
| CVE-2025-61663 | Grub2: missing unregister call for normal commands may lead to use-after-free | MEDIUM | 4.9 | Nov 18, 2025 |
| CVE-2025-61662 | Grub2: missing unregister call for gettext command may lead to use-after-free | HIGH | 7.8 | Nov 18, 2025 |
| CVE-2025-61661 | Grub2: grub2: out-of-bounds write via malicious usb device | MEDIUM | 4.8 | Nov 18, 2025 |
| CVE-2025-54771 | Grub2: use-after-free in grub_file_close() | MEDIUM | 4.9 | Nov 18, 2025 |
| CVE-2025-0686 | Grub2: romfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading dat | MEDIUM | 6.4 | Mar 3, 2025 |
| CVE-2025-0685 | Grub2: jfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data | MEDIUM | 6.4 | Mar 3, 2025 |
| CVE-2025-0684 | Grub2: reiserfs: integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data | MEDIUM | 6.4 | Mar 3, 2025 |
| CVE-2025-0678 | Grub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading data | HIGH | 7.8 | Mar 3, 2025 |
| CVE-2024-45782 | Grub2: fs/hfs: strcpy() using the volume name (fs/hfs.c:382) | HIGH | 7.8 | Mar 3, 2025 |
| CVE-2024-45778 | Grub2: fs/bfs: integer overflow in the bfs parser. | MEDIUM | 5.5 | Mar 3, 2025 |
| CVE-2024-45779 | Grub2: fs/bfs: integer overflow leads to heap oob read in the bfs parser | MEDIUM | 6.0 | Mar 3, 2025 |
| CVE-2024-45780 | Grub2: fs/tar: integer overflow causes heap oob write | MEDIUM | 6.7 | Mar 3, 2025 |
| CVE-2025-0689 | Grub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution | HIGH | 7.8 | Mar 3, 2025 |
| CVE-2025-1125 | Grub2: fs/hfs: integer overflow may lead to heap based out-of-bounds write | HIGH | 7.8 | Mar 3, 2025 |
| CVE-2024-45777 | Grub2: grub-core/gettext: integer overflow leads to heap oob write. | MEDIUM | 6.7 | Feb 19, 2025 |
| CVE-2024-56738 | grub2: Observable Timing Discrepancy resulting side-channel attacks | MEDIUM | 6.5 | Dec 29, 2024 |
| CVE-2024-56737 | grub2: heap-based buffer overflow | HIGH | 8.8 | Dec 29, 2024 |
| CVE-2024-2312 | grub2: grub-efi crashes upon `exit` | MEDIUM | 6.7 | Apr 5, 2024 |
| CVE-2024-1048 | Grub2: grub2-set-bootflag can be abused by local (pseudo-)users | LOW | 3.3 | Feb 6, 2024 |
| CVE-2023-4001 | Grub2: bypass the grub password protection feature | MEDIUM | 6.8 | Jan 15, 2024 |
| CVE-2023-4692 | Grub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code execution | HIGH | 7.8 | Oct 25, 2023 |
| CVE-2023-4693 | Grub2: out-of-bounds read at fs/ntfs.c | MEDIUM | 5.3 | Oct 25, 2023 |
Showing 1 to 25 of 54 CVEs