---
id: CVE-2025-1118
title: A flaw was found in grub2
summary: >-
  A flaw was found in grub2. Grub's dump command is not blocked when grub is in
  lockdown mode, which allows the user to read any memory information, and an
  attacker may leverage this in order to extract signatures, salts, and other
  sensiti…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-501
published: '2025-02-19'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1118'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:16154'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-1118'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2346137'
    label: secalert@redhat.com
  - url: >-
      https://git.savannah.gnu.org/cgit/grub.git/commit/?id=34824806ac6302f91e8cabaa41308eaced25725f
    label: secalert@redhat.com
  - url: 'https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00321
epssPercentile: 0.22527
ingestedAt: '2026-06-29T13:24:34.161Z'
---

## Overview

A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
