GRUB2 maintainers released a 73-patch security update bundle addressing 21 disclosed vulnerabilities across filesystem parsers, gettext, JPEG parsing, networking, GPG hooks, command handling, and module unloading. The flaws include heap out-of-bounds reads and writes, integer overflows, use-after-free conditions, information disclosure, denial of service, and potential arbitrary code execution. Oracle disclosed the CVEs publicly alongside the fixes, and researchers Nils Langius, B Horn, and Jonathan Bar Or were credited with responsible disclosure, with Oracle, Red Hat, and SUSE contributors helping prepare and upstream the patches.
Several of the vulnerabilities were described as capable of enabling Secure Boot bypass, while CVE-2025-0624 affects network boot and could allow remote code execution from the same network segment. Maintainers said full mitigation requires not only updated GRUB2 but also refreshed shim and other boot artifacts plus updated SBAT revocation data from vendors and Linux distributions; the UEFI dbx revocation list is not being used for this remediation round. The fixes were added upstream to the GRUB2 repository, with major distributions expected to ship updated packages.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On February 18, 2025, Daniel Kiper announced a 73-patch GRUB2 security bundle addressing numerous vulnerabilities found during a proactive hardening effort. The patches were added upstream to the GRUB2 git repository, and the notice said full mitigation would require updated GRUB2, shim, other boot artifacts, and SBAT revocation data from vendors and distributions.
On February 18, 2025, Oracle's Jan Setje-Eilers disclosed 21 GRUB CVEs via oss-security and stated that fixes were made public at the same time. The issues affected GRUB components including filesystem parsers, gettext, JPEG parsing, networking, GPG hooks, and command handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.