Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:3396 - Security Advisory
Issued:
2025-03-31
Updated:
2025-03-31

RHSA-2025:3396 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: grub2 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for grub2 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.

Security Fix(es):

  • grub2: net: Out-of-bounds write in grub_net_search_config_file() (CVE-2025-0624)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2346112 - CVE-2025-0624 grub2: net: Out-of-bounds write in grub_net_search_config_file()

CVEs

  • CVE-2025-0624

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
grub2-2.02-0.87.el7_9.15.src.rpm SHA-256: 8a355b68557fd667279c9569659914c2598a3b7af2695e212986fdc1783249a7
x86_64
grub2-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: c64577dc5342d06f1458925709f8a46d70ae60720bbbcaef4aa8d25ca6ce4a8f
grub2-common-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 3c14851c68edfeb813492ffe9d7a0466aa6600da889ecd336d103bdd10ec3ca2
grub2-debuginfo-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 4d51e0e76eb383460a7d89b98361ce5f360e084778da2a56f9d530559bd469f1
grub2-debuginfo-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 4d51e0e76eb383460a7d89b98361ce5f360e084778da2a56f9d530559bd469f1
grub2-efi-ia32-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 5c2d9900e59a282231972677d3bcfc9df73da8b87cee33a660e69fb404039cde
grub2-efi-ia32-cdboot-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 12c4a5ae1f49f2b945d81e8f340803c9efa30ffc6bf3fd17a514830b24062a8b
grub2-efi-ia32-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 99084e663789a7a984ef190dd5f54e25b9865eb882960f487d1f9460aca1410b
grub2-efi-x64-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: fe3428dab151819a21457cc18dab76d7e7753fac6273984883ea2fba1c56199f
grub2-efi-x64-cdboot-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 8413ac955f970cabc6e543f3e97a836e970f097a0f68ddab8847beeaf498be69
grub2-efi-x64-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 237f215e68c3ec93a38649fd636ede16720bec36e754924d81be77cd2e09f4ca
grub2-pc-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: c9bb26372652e2911ea9af8352fae560a887f369fa63454f95335d8bb8a0eafb
grub2-pc-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 795445fd56e085ca6c18cd20977fdd1454ad2d5e4e031286319c0b3617748458
grub2-ppc-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 7e1ace424294d48bb0cddcc608fc23794f3ec24c9b40172eaaaf8dc6ca414734
grub2-ppc64-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: b5561e2502e040c9b7b74794d5624b590daacb4a77628a76174138edf4962084
grub2-ppc64le-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 6506344dad1e97a60ef84c4a35045a0c0c75d94a3cc7f5c9d41b2e467b76538b
grub2-tools-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 8a7df893acf1e3000f0d776f1681b4421dfb11a5bdce889b806c14b2f637e876
grub2-tools-extra-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: bc5bf72e3ef8412193898760c213e12b49515b6c1333c3a984b57c4322597264
grub2-tools-minimal-2.02-0.87.el7_9.15.x86_64.rpm SHA-256: 03ebae78e4fcd50260e274d05250392bcf943b0795cd408e7fddfffd622c8714

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
grub2-2.02-0.87.el7_9.15.src.rpm SHA-256: 8a355b68557fd667279c9569659914c2598a3b7af2695e212986fdc1783249a7
ppc64
grub2-2.02-0.87.el7_9.15.ppc64.rpm SHA-256: 065621cdd8cebb40198616e9633dce4dd9e836fb24aafb36d20569a4d733a3e0
grub2-common-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 3c14851c68edfeb813492ffe9d7a0466aa6600da889ecd336d103bdd10ec3ca2
grub2-debuginfo-2.02-0.87.el7_9.15.ppc64.rpm SHA-256: 33b13b71083b684fff1470a5d2f75a14899d7432e1ce2e458555449a0ab55369
grub2-efi-ia32-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 99084e663789a7a984ef190dd5f54e25b9865eb882960f487d1f9460aca1410b
grub2-efi-x64-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 237f215e68c3ec93a38649fd636ede16720bec36e754924d81be77cd2e09f4ca
grub2-pc-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 795445fd56e085ca6c18cd20977fdd1454ad2d5e4e031286319c0b3617748458
grub2-ppc-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 7e1ace424294d48bb0cddcc608fc23794f3ec24c9b40172eaaaf8dc6ca414734
grub2-ppc64-2.02-0.87.el7_9.15.ppc64.rpm SHA-256: fe22e2b1f814c7e176d0ea271a60d3b8570b1483e08a30a5ef45940317667657
grub2-ppc64-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: b5561e2502e040c9b7b74794d5624b590daacb4a77628a76174138edf4962084
grub2-ppc64le-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 6506344dad1e97a60ef84c4a35045a0c0c75d94a3cc7f5c9d41b2e467b76538b
grub2-tools-2.02-0.87.el7_9.15.ppc64.rpm SHA-256: a855ed5ce1df96234b41736b23cd19605f9d0bb9965d27b8dd1f200fa42774cb
grub2-tools-extra-2.02-0.87.el7_9.15.ppc64.rpm SHA-256: 990fe0e2a7c44ae69011a5ca98c3cf843b1f7d1b7d0bd5ade79dc387c1f8186e
grub2-tools-minimal-2.02-0.87.el7_9.15.ppc64.rpm SHA-256: 3f1b4a873716156d6f1867815ebdb058743e4a41a2b0c092fc50d84130a2f49f

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
grub2-2.02-0.87.el7_9.15.src.rpm SHA-256: 8a355b68557fd667279c9569659914c2598a3b7af2695e212986fdc1783249a7
ppc64le
grub2-2.02-0.87.el7_9.15.ppc64le.rpm SHA-256: e1becfa7196a0a35e7ba75e0da306cba2f640d1828496b90f4b8d9efdc7435c5
grub2-common-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 3c14851c68edfeb813492ffe9d7a0466aa6600da889ecd336d103bdd10ec3ca2
grub2-debuginfo-2.02-0.87.el7_9.15.ppc64le.rpm SHA-256: a022d9be7bbc8738587ff59b170e2d91ea50e47be4fef4d065622c7d5418b6f0
grub2-efi-ia32-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 99084e663789a7a984ef190dd5f54e25b9865eb882960f487d1f9460aca1410b
grub2-efi-x64-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 237f215e68c3ec93a38649fd636ede16720bec36e754924d81be77cd2e09f4ca
grub2-pc-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 795445fd56e085ca6c18cd20977fdd1454ad2d5e4e031286319c0b3617748458
grub2-ppc-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 7e1ace424294d48bb0cddcc608fc23794f3ec24c9b40172eaaaf8dc6ca414734
grub2-ppc64-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: b5561e2502e040c9b7b74794d5624b590daacb4a77628a76174138edf4962084
grub2-ppc64le-2.02-0.87.el7_9.15.ppc64le.rpm SHA-256: 10398821beca68b9cc0b064db6a7f6189b9c9b377b5704430edc1c31e9e0d433
grub2-ppc64le-modules-2.02-0.87.el7_9.15.noarch.rpm SHA-256: 6506344dad1e97a60ef84c4a35045a0c0c75d94a3cc7f5c9d41b2e467b76538b
grub2-tools-2.02-0.87.el7_9.15.ppc64le.rpm SHA-256: 5d4ede1156969af8922aff95d1345c07df1df8fea34a967119f00ef8ff8b0fa8
grub2-tools-extra-2.02-0.87.el7_9.15.ppc64le.rpm SHA-256: e449a57751de10d258992835a4c3f6ca418fe8788dfa90dc5f6c5b4ba64a693c
grub2-tools-minimal-2.02-0.87.el7_9.15.ppc64le.rpm SHA-256: 8f8ef5a90d8f51799ce47ed3b46707c293d607ad1ec9b7398addaa6410dba865

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility