Database/Firmware, BMC & network fabric
GRUB2 (dump command lockdown): The dump command was not disabled under Secure Boot lockdown, letting a privileged user
CVE-2025-1118Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
The dump command was not disabled under Secure Boot lockdown, letting a privileged user read arbitrary memory at boot. That includes anything the firmware left in RAM - most usefully, key material and Secure Boot state. Low CVSS, high value as a reconnaissance primitive before a real bypass.
Who can reach it
Local privileged user at the GRUB shell.
What to do
grub2 package update + reboot. A GRUB password limits access to the shell in the meantime, but does not fix the lockdown gap.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.