Database/Firmware, BMC & network fabric
GRUB2 (commands/gpg): Module unload leaves registered hooks behind, so GRUB later calls through freed function pointers
CVE-2025-0622Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
Module unload leaves registered hooks behind, so GRUB later calls through freed function pointers. Notable because the affected module is the one meant to verify signatures - the bug is in the verification machinery itself.
Who can reach it
Local, via GRUB command sequences or grub.cfg.
What to do
grub2 package update + reboot. Part of the same February 2025 distro update as the rest of the batch.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.