{
  "cves": [
    "CVE-2025-0624"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.02-164.0.2]\n- fs/ext2: Rework out-of-bounds read for inline and external extents [Orabug: 37829911]\n\n[2.02-164.0.1]\n- Update grub2 dependencies to match new Secure Boot certificate chain of trust [Orabug: 37766761]\n- Fix typo in SBAT metadata [Orabug: 37693946]\n- Allow installation of grub2 only with shim-aa64 that allows booting it [Orabug: 37693946]\n- net/dns: Fix removal of DNS server [Orabug: 37539625]\n- net/dns: Simplify error handling of recv_hook() function [Orabug: 37539625]\n- net/dns: Add debugging messages in recv_hook() function [Orabug: 37539625]\n- net/dns: Fix lookup error when no IPv6 is returned [Orabug: 37539625]\n- Use correct os_name on OL\n- Backport the support for setting custom kernels as default kernels [Orabug: 36690061]\n- Restore correct SBAT entries\n- Replaced bugzilla.oracle.com references [Orabug: 35475894]\n- efinet: Close and reopen card on failure [Orabug: 35126950]\n- Fix CVE-2022-3775 [Orabug: 34867710]\n- Bump SBAT metadata for grub to 3 [Orabug: 34871758]\n- Enable signing on aarch64\n- Don't try to switch to a BLS config if GRUB_ENABLE_BLSCFG is already set (Javier Martinez Canillas) [Orabug: 34375996]\n- Enable back btrfs module by default [Orabug: 34377188]\n- Backport upstream SNP protocol fixes [Orabug: 34195100]\n- Rebase Fix EFI loader kernel image allocation patch, adapt it to new NX code [Orabug: 34352232]\n- enable multiboot2 [Orabug: 34285558]\n- backport arm64: Fix EFI loader kernel image allocation [Orabug: 33702462]\n- backport Arm: check for the PE magic for the compiled arch [Orabug: 33702462]\n- Backport some better script logic for BTRFS support [Orabug: 32448171]\n- Do not add shim and grub certificate deps for aarch64 packages [Orabug: 32670033]\n- Update Oracle SBAT data [Orabug: 32670033]\n- Use new signing certificate [Orabug: 32670033]\n- Fix various coverity issues [Orabug: 32530657]\n- Set proper blsdir if /boot is on btrfs rootfs [Orabug: 32063327]\n- Add CVE-2020-15706, CVE-2020-15707 to the list [Orabug: 31225072]\n- honor /etc/sysconfig/kernel DEFAULTKERNEL setting for BLS [Orabug: 30643497]\n- set EFIDIR as redhat for additional grub2 tools [Orabug: 29875597]\n- Update upstream references [Orabug: 26388226]\n- Insert Unbreakable Enterprise Kernel text into BLS config file [Orabug: 29417955]\n- fix symlink removal scriptlet, to be executed only on removal [Orabug: 19231481]\n- Fix comparison in patch for 18504756\n- Remove symlink to grub environment file during uninstall on EFI platforms [Orabug: 19231481]\n- Put 'with' in menuentry instead of 'using' [Orabug: 18504756]\n- Use different titles for UEK and RHCK kernels [Orabug: 18504756]\n\n[2.02-164]\n- Bump NVR to sign the build\n- Resolves: #RHEL-85627\n\n[2.02-163]\n- fs/xfs: Synced xfs to latest\n- Resolves: #RHEL-85627\n\n[2.02-162]\n- ieee1275/ofnet: Fix grub_malloc() removed after added safe\n- Remove 'fs/ntfs: Implement attribute verification' patch\n- Related: #RHEL-79837\n\n[2.02-161]\n- Add Several CVE fixes\n- Resolves CVE-2024-45775 CVE-2025-0624\n- Resolves: #RHEL-75735\n- Resolves: #RHEL-79837",
  "id": "ELSA-2025-3367",
  "ovalId": "oval:com.oracle.elsa:def:20253367",
  "source": "oracle_linux",
  "title": "ELSA-2025-3367:  grub2 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-3367.html"
}