CVE-2025-0678
Alma Linux vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2025-0678) was discovered in GRUB2's squash4 filesystem module. The flaw was disclosed on February 18, 2025, affecting GRUB2 versions up to 2.12. The vulnerability stems from improper integer overflow checks when processing filesystem geometry parameters (NVD, Openwall).

Technical details

The vulnerability occurs when GRUB2's squash4 filesystem module processes user-controlled parameters from filesystem geometry to determine internal buffer sizes. Due to improper integer overflow checks, a maliciously crafted filesystem can cause buffer size calculations to overflow, resulting in grub_malloc() operations with smaller-than-expected sizes. This leads to heap-based out-of-bounds writes during data reading through the direct_read() function. The vulnerability has received a CVSS v3.1 base score of 7.8 (HIGH) from NVD and 6.4 (MEDIUM) from Red Hat (NVD).

Impact

The vulnerability can be exploited to corrupt GRUB's internal critical data, potentially leading to arbitrary code execution and bypass of secure boot protections. This poses a significant security risk to affected systems, particularly in environments where secure boot is relied upon for system integrity (NVD, Debian).

Exploitability

The vulnerability requires local access and high privileges to exploit. The attack complexity is considered high, as it requires the creation of a maliciously crafted squash4 filesystem. The vulnerability has been assigned CWE-190 (Integer Overflow or Wraparound) and CWE-787 (Out-of-bounds Write) classifications (NVD).

Mitigation and workarounds

A fix has been released in GRUB2 version 2.12-7 for Debian systems. Red Hat Enterprise Linux 7.0, 8.0, 9.0, and OpenShift Container Platform 4.0 are affected and require updates. System administrators are advised to apply the available patches as soon as possible (Debian).

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68480HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-uek-modules-usb
NoYesAug 06, 2026
CVE-2026-64582HIGH7.8
  • Linux Kernel logoLinux Kernel
  • libperf
NoYesAug 05, 2026
CVE-2026-18649HIGH7.5
  • Rocky Linux logoRocky Linux
  • gstreamer1-plugins-good-gtk
NoYesAug 06, 2026
CVE-2026-64576HIGH7.1
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesAug 05, 2026
CVE-2026-64579MEDIUM4.1
  • Linux Kernel logoLinux Kernel
  • kernel-64k-uki-virt-addons
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management