Description

A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.

INFO

Published Date :

2025-02-19T17:54:27.651Z

Last Modified :

2026-03-24T22:45:30.519Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-1118 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux
  • Openshift

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact