• About TC
  • Affiliate Disclaimer
  • Privacy Policy
  • TOS
  • Contact
Monday, June 16, 2025
Techcratic
  • TC
  • AI
    Artificial Intelligence

    Amazon Nova Lite enables Bito to offer a free tier option for its AI-powered code reviews

    Artificial Intelligence

    Bridging the Gap: New Datasets Push Recommender Research Toward Real-World Scale

    Artificial Intelligence

    7 Python Errors That Are Actually Features

    Artificial Intelligence

    10 Awesome OCR Models for 2025

    Artificial Intelligence

    5 Error Handling Patterns in Python (Beyond Try-Except)

    Artificial Intelligence

    Top 5 Alternative Data Career Paths and How to Learn Them for Free

    Artificial Intelligence

    Implementing Machine Learning Pipelines with Apache Spark

    Artificial Intelligence

    Learn Power BI for Free This Week

    Artificial Intelligence

    Build GraphRAG applications using Amazon Bedrock Knowledge Bases

  • Crypto
    Metaplanet Acquires Additional 1,112 Bitcoin, Total Holdings Reach 10,000 BTC

    Metaplanet Acquires Additional 1,112 Bitcoin, Total Holdings Reach 10,000 BTC

    Crypto to “Become Part of All Sectors” Under Trump: Kevin O’Leary

    Metaplanet Issues Fresh $210M Bonds to Evo Fund

    Bitcoin Going to $1M: Saylor’s Call Revives Interest in Adam Back’s 21M BTC Order

    Bitcoin Going to $1M: Saylor’s Call Revives Interest in Adam Back’s 21M BTC Order

    Bitcoin Eyes $30T Treasury Store of Value Market, Says Bitwise CEO

    Bitcoin Eyes $30T Treasury Store of Value Market, Says Bitwise CEO

    ZKJ Token Plummets More Than 60% in Flash Crash Amid Rug-Pull Allegations

    ZKJ Token Plummets More Than 60% in Flash Crash Amid Rug-Pull Allegations

    Bitcoin Holding $105K During War Is Bullish for Crypto

    Bitcoin Holding $105K During War Is Bullish for Crypto

    Saylor Signals Another Bitcoin Buy—Orange Dots Strike Again

    Saylor Signals Another Bitcoin Buy—Orange Dots Strike Again

    XRP Technical Analysis: Downtrend Dominates—Is the $2.05 Floor About to Collapse?

    XRP Technical Analysis: Downtrend Dominates—Is the $2.05 Floor About to Collapse?

    Best Presales to Buy Today – Which Coins Are Poised for a Breakout?

    Last 72 Hours to Join $49M Raise

  • Cybersecurity
    Cybersecurity

    AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

    Cybersecurity

    How to Address the Expanding Security Risk

    Cybersecurity

    ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks

    Cybersecurity

    5 Lessons from River Island

    Cybersecurity

    INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure

    Cybersecurity

    SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords

    Cybersecurity

    Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud

    Cybersecurity

    Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps

    Cybersecurity

    Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account

  • Deals
    B221000 Black Toner Cartridge B/MB2236 Replacement for Lexmark B221000 Toner Cartridge…

    B221000 Black Toner Cartridge B/MB2236 Replacement for Lexmark B221000 Toner Cartridge…

    Lexar 1TB Professional Go Portable SSD w/Hub, Supports Apple 4K 60fps ProRes, Up to…

    Lexar 1TB Professional Go Portable SSD w/Hub, Supports Apple 4K 60fps ProRes, Up to…

    Kingston NV3 1TB M.2 2280 NVMe SSD | PCIe 4.0 Gen 4×4 | Up to 6000 MB/s | SNV3S/1000G

    Kingston NV3 1TB M.2 2280 NVMe SSD | PCIe 4.0 Gen 4×4 | Up to 6000 MB/s | SNV3S/1000G

    Intel Core Ultra 7 Desktop Processor 265K – 20 cores (8 P-cores + 12 E-cores) up to 5.5…

    Intel Core Ultra 7 Desktop Processor 265K – 20 cores (8 P-cores + 12 E-cores) up to 5.5…

    Hitachi FIJ0038 Fuel Injector

    Hitachi FIJ0038 Fuel Injector

    EVGA Supernova 1300 P+, 80+ Platinum 1300W, Fully Modular, 10 Year Warranty, Includes…

    EVGA Supernova 1300 P+, 80+ Platinum 1300W, Fully Modular, 10 Year Warranty, Includes…

    Logitech G502 X Plus Wireless Gaming Mouse – LIGHTSPEED Optical, LIGHTFORCE Switches,…

    Logitech G502 X Plus Wireless Gaming Mouse – LIGHTSPEED Optical, LIGHTFORCE Switches,…

    Cable Matters 8-Pack Snagless Cat 5e Ethernet Cable – 5ft, Gigabit Cat5e Cable, Cat5e…

    Cable Matters 8-Pack Snagless Cat 5e Ethernet Cable – 5ft, Gigabit Cat5e Cable, Cat5e…

    Logitech iPad Pro 12.9 inch Keyboard Case | SLIM COMBO with Detachable, Backlit,…

    Logitech iPad Pro 12.9 inch Keyboard Case | SLIM COMBO with Detachable, Backlit,…

  • Gaming
    WWE 2K25 Review – Two Steps Forward, One Step Back

    WWE 2K25 Review – Two Steps Forward, One Step Back

    Honest Game Trailers | WoW: Wrath of the Lich King

    Honest Game Trailers | WoW: Wrath of the Lich King

    Hello Neighbor – Finland Story | Full Game Walkthrough

    Hello Neighbor – Finland Story | Full Game Walkthrough

    Elden Ring NIGHTREIGN Early Reviews Say It All….

    Elden Ring NIGHTREIGN Early Reviews Say It All….

    Zelda Oot episode 2 More tutorials

    Zelda Oot episode 2 More tutorials

    Zelda: The Minish Cap | Episode 13

    Zelda: The Minish Cap | Episode 13

    The Legend of Zelda: Breath of the Wild – Shada Naw Shrine Walkthrough [HD 1080P]

    The Legend of Zelda: Breath of the Wild – Shada Naw Shrine Walkthrough [HD 1080P]

    Zelda Breath of the Wild – All Rito Weapons (Complete Set Location)

    Zelda Breath of the Wild – All Rito Weapons (Complete Set Location)

    Walkthrough FR l Zelda Ocarina Of Time l Premier Flacon

    Walkthrough FR l Zelda Ocarina Of Time l Premier Flacon

  • Tesla
    LUCKEASY 2PCS Storage Box Compatible with Tesla Cybertruck 2024 2023 Center Console…

    LUCKEASY 2PCS Storage Box Compatible with Tesla Cybertruck 2024 2023 Center Console…

    Tesla on ‘self-driving’ gets stuck on train track and hit by train

    Tesla on ‘self-driving’ gets stuck on train track and hit by train

    Level 1/2 Tesla Charger – 16A 3.84KW Mobile EV Charging with 240V NEMA 6-20 Plug, 5-15…

    Level 1/2 Tesla Charger – 16A 3.84KW Mobile EV Charging with 240V NEMA 6-20 Plug, 5-15…

    Upgrade fit Tesla Model Y (2019-2023) Center Console Wireless Charger Mat – Silicone…

    Upgrade fit Tesla Model Y (2019-2023) Center Console Wireless Charger Mat – Silicone…

    Torx Plus Socket, 5-External Torx Socket 1/4″ Dr 10EPR Compatible With Tesla Model 3…

    Torx Plus Socket, 5-External Torx Socket 1/4″ Dr 10EPR Compatible With Tesla Model 3…

    Car Seat Organizers,Multi-functional Back Seat Protectors, Storage Pouches, and Tray…

    Car Seat Organizers,Multi-functional Back Seat Protectors, Storage Pouches, and Tray…

    AOHI USB C Car Charger, PD 45W&QC 30W 2 Port Type-C Fast Charging Car Charger Lighter…

    AOHI USB C Car Charger, PD 45W&QC 30W 2 Port Type-C Fast Charging Car Charger Lighter…

    Roof Sunshades for Tesla Model 3 2025, Upgraded 3.0 Sunroof Shade Sunshade Roof Sun…

    Roof Sunshades for Tesla Model 3 2025, Upgraded 3.0 Sunroof Shade Sunshade Roof Sun…

    SOOPII for Tesla Phone Mount,Strongest Magnetic Monitor Mount for Tesla 3/Y…

    SOOPII for Tesla Phone Mount,Strongest Magnetic Monitor Mount for Tesla 3/Y…

  • UFO
    Did Ancient astronauts visit Earth?? new evidence fuels extraterrestrial Theories! #viral #history

    Did Ancient astronauts visit Earth?? new evidence fuels extraterrestrial Theories! #viral #history

    INFUNLY 4pcs Solar System Patches Iron on Sequin Planet Embroidery Patch Rainbow UFO Patch Space Sew on Patch Spacecraft Patch Celestial Applique for DIY Clothing Jeans Bags Jacket Backpack Hat

    INFUNLY 4pcs Solar System Patches Iron on Sequin Planet Embroidery Patch Rainbow UFO Patch Space Sew on Patch Spacecraft Patch Celestial Applique for DIY Clothing Jeans Bags Jacket Backpack Hat

    UFO Cover Up – They Want You Confused About the Truth!

    UFO Cover Up – They Want You Confused About the Truth!

    Nitro Green for Men – 3.4 oz EDP Spray

    Nitro Green for Men – 3.4 oz EDP Spray

    Argentinian Town Has One Of The Best Documented Mass UFO Sightings | The Unexplained Files

    Football Fan Patch Trucker Hat – Netted Snapback Baseball Cap with Team Design for Men & Women

    Football Fan Patch Trucker Hat – Netted Snapback Baseball Cap with Team Design for Men & Women

    [F4A] Alien researcher reports her findings [Scientist Speaker] [Research]

    [F4A] Alien researcher reports her findings [Scientist Speaker] [Research]

    Secrets of the Moon (S11, E11) | Ancient Aliens | Full Episode

    Secrets of the Moon (S11, E11) | Ancient Aliens | Full Episode

    UFOs Over Arizona: A True History of Extraterrestrial Encounters in the Grand Canyon State

    UFOs Over Arizona: A True History of Extraterrestrial Encounters in the Grand Canyon State

No Result
View All Result
  • TC
  • AI
    Artificial Intelligence

    Amazon Nova Lite enables Bito to offer a free tier option for its AI-powered code reviews

    Artificial Intelligence

    Bridging the Gap: New Datasets Push Recommender Research Toward Real-World Scale

    Artificial Intelligence

    7 Python Errors That Are Actually Features

    Artificial Intelligence

    10 Awesome OCR Models for 2025

    Artificial Intelligence

    5 Error Handling Patterns in Python (Beyond Try-Except)

    Artificial Intelligence

    Top 5 Alternative Data Career Paths and How to Learn Them for Free

    Artificial Intelligence

    Implementing Machine Learning Pipelines with Apache Spark

    Artificial Intelligence

    Learn Power BI for Free This Week

    Artificial Intelligence

    Build GraphRAG applications using Amazon Bedrock Knowledge Bases

  • Crypto
    Metaplanet Acquires Additional 1,112 Bitcoin, Total Holdings Reach 10,000 BTC

    Metaplanet Acquires Additional 1,112 Bitcoin, Total Holdings Reach 10,000 BTC

    Crypto to “Become Part of All Sectors” Under Trump: Kevin O’Leary

    Metaplanet Issues Fresh $210M Bonds to Evo Fund

    Bitcoin Going to $1M: Saylor’s Call Revives Interest in Adam Back’s 21M BTC Order

    Bitcoin Going to $1M: Saylor’s Call Revives Interest in Adam Back’s 21M BTC Order

    Bitcoin Eyes $30T Treasury Store of Value Market, Says Bitwise CEO

    Bitcoin Eyes $30T Treasury Store of Value Market, Says Bitwise CEO

    ZKJ Token Plummets More Than 60% in Flash Crash Amid Rug-Pull Allegations

    ZKJ Token Plummets More Than 60% in Flash Crash Amid Rug-Pull Allegations

    Bitcoin Holding $105K During War Is Bullish for Crypto

    Bitcoin Holding $105K During War Is Bullish for Crypto

    Saylor Signals Another Bitcoin Buy—Orange Dots Strike Again

    Saylor Signals Another Bitcoin Buy—Orange Dots Strike Again

    XRP Technical Analysis: Downtrend Dominates—Is the $2.05 Floor About to Collapse?

    XRP Technical Analysis: Downtrend Dominates—Is the $2.05 Floor About to Collapse?

    Best Presales to Buy Today – Which Coins Are Poised for a Breakout?

    Last 72 Hours to Join $49M Raise

  • Cybersecurity
    Cybersecurity

    AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

    Cybersecurity

    How to Address the Expanding Security Risk

    Cybersecurity

    ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks

    Cybersecurity

    5 Lessons from River Island

    Cybersecurity

    INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure

    Cybersecurity

    SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords

    Cybersecurity

    Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud

    Cybersecurity

    Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps

    Cybersecurity

    Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account

  • Deals
    B221000 Black Toner Cartridge B/MB2236 Replacement for Lexmark B221000 Toner Cartridge…

    B221000 Black Toner Cartridge B/MB2236 Replacement for Lexmark B221000 Toner Cartridge…

    Lexar 1TB Professional Go Portable SSD w/Hub, Supports Apple 4K 60fps ProRes, Up to…

    Lexar 1TB Professional Go Portable SSD w/Hub, Supports Apple 4K 60fps ProRes, Up to…

    Kingston NV3 1TB M.2 2280 NVMe SSD | PCIe 4.0 Gen 4×4 | Up to 6000 MB/s | SNV3S/1000G

    Kingston NV3 1TB M.2 2280 NVMe SSD | PCIe 4.0 Gen 4×4 | Up to 6000 MB/s | SNV3S/1000G

    Intel Core Ultra 7 Desktop Processor 265K – 20 cores (8 P-cores + 12 E-cores) up to 5.5…

    Intel Core Ultra 7 Desktop Processor 265K – 20 cores (8 P-cores + 12 E-cores) up to 5.5…

    Hitachi FIJ0038 Fuel Injector

    Hitachi FIJ0038 Fuel Injector

    EVGA Supernova 1300 P+, 80+ Platinum 1300W, Fully Modular, 10 Year Warranty, Includes…

    EVGA Supernova 1300 P+, 80+ Platinum 1300W, Fully Modular, 10 Year Warranty, Includes…

    Logitech G502 X Plus Wireless Gaming Mouse – LIGHTSPEED Optical, LIGHTFORCE Switches,…

    Logitech G502 X Plus Wireless Gaming Mouse – LIGHTSPEED Optical, LIGHTFORCE Switches,…

    Cable Matters 8-Pack Snagless Cat 5e Ethernet Cable – 5ft, Gigabit Cat5e Cable, Cat5e…

    Cable Matters 8-Pack Snagless Cat 5e Ethernet Cable – 5ft, Gigabit Cat5e Cable, Cat5e…

    Logitech iPad Pro 12.9 inch Keyboard Case | SLIM COMBO with Detachable, Backlit,…

    Logitech iPad Pro 12.9 inch Keyboard Case | SLIM COMBO with Detachable, Backlit,…

  • Gaming
    WWE 2K25 Review – Two Steps Forward, One Step Back

    WWE 2K25 Review – Two Steps Forward, One Step Back

    Honest Game Trailers | WoW: Wrath of the Lich King

    Honest Game Trailers | WoW: Wrath of the Lich King

    Hello Neighbor – Finland Story | Full Game Walkthrough

    Hello Neighbor – Finland Story | Full Game Walkthrough

    Elden Ring NIGHTREIGN Early Reviews Say It All….

    Elden Ring NIGHTREIGN Early Reviews Say It All….

    Zelda Oot episode 2 More tutorials

    Zelda Oot episode 2 More tutorials

    Zelda: The Minish Cap | Episode 13

    Zelda: The Minish Cap | Episode 13

    The Legend of Zelda: Breath of the Wild – Shada Naw Shrine Walkthrough [HD 1080P]

    The Legend of Zelda: Breath of the Wild – Shada Naw Shrine Walkthrough [HD 1080P]

    Zelda Breath of the Wild – All Rito Weapons (Complete Set Location)

    Zelda Breath of the Wild – All Rito Weapons (Complete Set Location)

    Walkthrough FR l Zelda Ocarina Of Time l Premier Flacon

    Walkthrough FR l Zelda Ocarina Of Time l Premier Flacon

  • Tesla
    LUCKEASY 2PCS Storage Box Compatible with Tesla Cybertruck 2024 2023 Center Console…

    LUCKEASY 2PCS Storage Box Compatible with Tesla Cybertruck 2024 2023 Center Console…

    Tesla on ‘self-driving’ gets stuck on train track and hit by train

    Tesla on ‘self-driving’ gets stuck on train track and hit by train

    Level 1/2 Tesla Charger – 16A 3.84KW Mobile EV Charging with 240V NEMA 6-20 Plug, 5-15…

    Level 1/2 Tesla Charger – 16A 3.84KW Mobile EV Charging with 240V NEMA 6-20 Plug, 5-15…

    Upgrade fit Tesla Model Y (2019-2023) Center Console Wireless Charger Mat – Silicone…

    Upgrade fit Tesla Model Y (2019-2023) Center Console Wireless Charger Mat – Silicone…

    Torx Plus Socket, 5-External Torx Socket 1/4″ Dr 10EPR Compatible With Tesla Model 3…

    Torx Plus Socket, 5-External Torx Socket 1/4″ Dr 10EPR Compatible With Tesla Model 3…

    Car Seat Organizers,Multi-functional Back Seat Protectors, Storage Pouches, and Tray…

    Car Seat Organizers,Multi-functional Back Seat Protectors, Storage Pouches, and Tray…

    AOHI USB C Car Charger, PD 45W&QC 30W 2 Port Type-C Fast Charging Car Charger Lighter…

    AOHI USB C Car Charger, PD 45W&QC 30W 2 Port Type-C Fast Charging Car Charger Lighter…

    Roof Sunshades for Tesla Model 3 2025, Upgraded 3.0 Sunroof Shade Sunshade Roof Sun…

    Roof Sunshades for Tesla Model 3 2025, Upgraded 3.0 Sunroof Shade Sunshade Roof Sun…

    SOOPII for Tesla Phone Mount,Strongest Magnetic Monitor Mount for Tesla 3/Y…

    SOOPII for Tesla Phone Mount,Strongest Magnetic Monitor Mount for Tesla 3/Y…

  • UFO
    Did Ancient astronauts visit Earth?? new evidence fuels extraterrestrial Theories! #viral #history

    Did Ancient astronauts visit Earth?? new evidence fuels extraterrestrial Theories! #viral #history

    INFUNLY 4pcs Solar System Patches Iron on Sequin Planet Embroidery Patch Rainbow UFO Patch Space Sew on Patch Spacecraft Patch Celestial Applique for DIY Clothing Jeans Bags Jacket Backpack Hat

    INFUNLY 4pcs Solar System Patches Iron on Sequin Planet Embroidery Patch Rainbow UFO Patch Space Sew on Patch Spacecraft Patch Celestial Applique for DIY Clothing Jeans Bags Jacket Backpack Hat

    UFO Cover Up – They Want You Confused About the Truth!

    UFO Cover Up – They Want You Confused About the Truth!

    Nitro Green for Men – 3.4 oz EDP Spray

    Nitro Green for Men – 3.4 oz EDP Spray

    Argentinian Town Has One Of The Best Documented Mass UFO Sightings | The Unexplained Files

    Football Fan Patch Trucker Hat – Netted Snapback Baseball Cap with Team Design for Men & Women

    Football Fan Patch Trucker Hat – Netted Snapback Baseball Cap with Team Design for Men & Women

    [F4A] Alien researcher reports her findings [Scientist Speaker] [Research]

    [F4A] Alien researcher reports her findings [Scientist Speaker] [Research]

    Secrets of the Moon (S11, E11) | Ancient Aliens | Full Episode

    Secrets of the Moon (S11, E11) | Ancient Aliens | Full Episode

    UFOs Over Arizona: A True History of Extraterrestrial Encounters in the Grand Canyon State

    UFOs Over Arizona: A True History of Extraterrestrial Encounters in the Grand Canyon State

No Result
View All Result
Techcratic
No Result
View All Result
Home Hacker News

Microsoft Discovers GRUB2, U-Boot, and Barebox Bootloader Flaws with Copilot

Hacker News by Hacker News
April 1, 2025
in Hacker News
Reading Time: 7 mins read
127 3
A A
0

Aman Mishra
2025-04-01 07:21:00
gbhackers.com

Microsoft has disclosed the discovery of multiple critical vulnerabilities within the GRUB2, U-Boot, and Barebox bootloaders, leveraging its AI-driven Security Copilot platform for advanced threat analysis.

These bootloaders, integral to the Unified Extensible Firmware Interface (UEFI) Secure Boot framework and widely deployed in embedded systems, were found to contain exploitable flaws that could compromise system integrity, enable privilege escalation, and bypass Secure Boot protections.

The findings have significant implications for device security across Linux-based systems and embedded environments.

Technical Analysis of Vulnerabilities

The vulnerabilities uncovered span critical areas of bootloader functionality, particularly in filesystem parsing routines.

In GRUB2, integer overflow vulnerabilities were identified in symbolic link handling within filesystem modules such as JFS, UDF, and HFS.

These flaws could allow attackers to craft malicious filesystems that trigger memory corruption or arbitrary code execution during bootloader execution.

Exploitation of these vulnerabilities poses a direct threat to Secure Boot mechanisms by enabling attackers to inject unauthorized code into the boot sequence or deploy persistent malware that survives system reinstallation.

Similarly, U-Boot and Barebox were found to share code-level vulnerabilities due to their reliance on overlapping codebases with GRUB2.

For instance, U-Boot exhibited a critical flaw (CVE-2025-26726) in its SquashFS directory parsing logic that could lead to buffer overflows under certain conditions.

Barebox inherited similar filesystem-related weaknesses due to shared architectural components.

While exploitation of these vulnerabilities in U-Boot and Barebox typically requires physical access to the device, their presence underscores systemic risks associated with code reuse across open-source projects.

Microsoft’s Security Copilot played a pivotal role in identifying these vulnerabilities by automating the analysis of high-risk code segments.

The AI-driven platform leveraged natural language processing (NLP) and machine learning models trained on vulnerability patterns to pinpoint exploitable areas within bootloader source code.

This approach significantly reduced manual auditing time while uncovering additional flaws that may have otherwise gone unnoticed.

In adherence to responsible disclosure practices, Microsoft engaged directly with the maintainers of GRUB2, U-Boot, and Barebox to facilitate remediation efforts.

Security patches addressing these vulnerabilities were released on February 18-19, 2025.

GRUB2 maintainers implemented additional security measures by disabling certain OS modules when Secure Boot is enabled and enhancing revocation management via updates to the SBAT (Secure Boot Advanced Targeting) mechanism.

CopilotCopilot
GRUB2 loading schema

The disclosed vulnerabilities are tracked under multiple CVEs, including CVE-2025-0677 for GRUB2’s integer overflow issue and CVE-2025-26726 for U-Boot’s SquashFS parsing flaw.

These updates underscore the importance of robust patch management practices within the open-source ecosystem.

Key Findings: Filesystem Vulnerabilities

Microsoft focused its analysis on filesystem functionalities within GRUB2 after Security Copilot flagged them as high-risk areas for potential vulnerabilities.

Using the JFFS2 filesystem as a test case, Security Copilot identified multiple security issues, including an integer overflow vulnerability that was confirmed through manual review.

Security Copilot spotting an integer overflow vulnerability and suggesting a fix

This vulnerability allowed an attacker to manipulate symbolic link resolution in the JFS module, leading to memory corruption. Specifically:

  • The size variable in the JFS symbolic link resolution function was vulnerable to overflow due to its definition as a 64-bit unsigned integer (uint64_t).
  • An attacker could supply a malicious filesystem image with a maximum value for size (0xFFFFFFFFFFFFFFFF), causing an integer overflow during the size+1 calculation.
  • This resulted in an allocation of a zero-byte memory chunk, which was subsequently overwritten with attacker-controlled data, enabling arbitrary memory corruption.
Vulnerable symbolic link resolution code in JFS

Similar vulnerabilities were found across other GRUB2 filesystem modules:

Module Vulnerability CVE
UFS Integer overflow in symbolic link handling CVE-2025-0677
Squash4 Integer overflow in file reads CVE-2025-0678
ReiserFS Integer overflow in symbolic link handling CVE-2025-0684
JFS Integer overflow in symbolic link handling CVE-2025-0685
RomFS Integer overflow in symbolic link handling CVE-2025-0686
UDF Out-of-bounds block reads CVE-2025-0689
HFS Wild strcpy usage on non-NUL-terminated strings during mounting CVE-2024-56737

Microsoft also reported a cryptographic side-channel attack vulnerability (CVE-2024-56738) due to non-constant time memory comparisons in the grub_crypto_memcmp function.

Extending Analysis to Other Bootloaders

Variant analysis revealed that U-Boot and Barebox shared similar vulnerabilities due to code reuse from GRUB2. For example:

  • U-Boot: SquashFS directory table parsing (CVE-2025-26726) and nested file reading buffer overflows were identified.
  • Barebox: EXT4 symlink resolution (CVE-2025-26723) and CramFS symlink parsing flaws were detected.

While exploitation of these vulnerabilities often requires physical access in embedded systems, their presence underscores systemic risks associated with shared open-source codebases.

Vulnerabilities at this level can undermine critical security layers such as UEFI Secure Boot, which is designed to validate cryptographic signatures of bootloader binaries before execution.

Microsoft emphasized that while AI-driven tools like Security Copilot enhance defenders’ capabilities in identifying threats, they also raise concerns about adversarial use for vulnerability exploitation.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup – Try for Free

Source Link


Keep your files stored safely and securely with the SanDisk 2TB Extreme Portable SSD. With over 69,505 ratings and an impressive 4.6 out of 5 stars, this product has been purchased over 8K+ times in the past month. At only $129.99, this Amazon’s Choice product is a must-have for secure file storage.

Help keep private content private with the included password protection featuring 256-bit AES hardware encryption. Order now for just $129.99 on Amazon!


Start your free Amazon Prime trial
today and unlock unlimited streaming and more!

Help Power Techcratic’s Future – Scan To Support

If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.

As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!

BITCOIN

Bitcoin Logo

Bitcoin QR Code

bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge

Scan the QR code with your crypto wallet app

DOGECOIN

Dogecoin Logo

Dogecoin QR Code

D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA

Scan the QR code with your crypto wallet app

ETHEREUM

Ethereum Logo

Ethereum QR Code

0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a

Scan the QR code with your crypto wallet app

Please read the Privacy and Security Disclaimer on how Techcratic handles your support.

Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.

Tags: Hacker News
Previous Post

Embracer studio Eidos-Montreal has laid off 75 employees

Next Post

Google Maps is giving your ETA screen a glow-up on Android

Hacker News

Hacker News

Stay updated with Hacker News, where technology meets entrepreneurial spirit. Get the latest on tech trends, startup news, and discussions from the tech community. Read the latest updates here at Techcratic.

Related Posts

Solving LinkedIn Queens with APL
Hacker News

Solving LinkedIn Queens with APL

June 16, 2025
1.3k
KAIST NEWS CENTER
Hacker News

KAIST NEWS CENTER

June 15, 2025
1.3k
How fast can the RPython GC allocate?
Hacker News

How fast can the RPython GC allocate?

June 15, 2025
1.3k
Biofuels Policy, a Mainstay of American Agriculture, Has Been a Failure for the Climate, a New Report Claims
Hacker News

Biofuels Policy, a Mainstay of American Agriculture, Has Been a Failure for the Climate, a New Report Claims

June 15, 2025
1.3k
SakanaAI/text-to-lora: Hypernetworks that adapt LLMs for specific benchmark tasks using only textual task description as the input
Hacker News

SakanaAI/text-to-lora: Hypernetworks that adapt LLMs for specific benchmark tasks using only textual task description as the input

June 15, 2025
1.3k
tanelp/tiny-diffusion: A minimal PyTorch implementation of probabilistic diffusion models for 2D datasets.
Hacker News

tanelp/tiny-diffusion: A minimal PyTorch implementation of probabilistic diffusion models for 2D datasets.

June 15, 2025
1.3k
How we investigated Amsterdam’s attempt to build a ‘fair’ fraud detection model
Hacker News

How we investigated Amsterdam’s attempt to build a ‘fair’ fraud detection model

June 14, 2025
1.3k
Waymo rides cost more than Uber or Lyft — and people are paying anyway
Hacker News

Waymo rides cost more than Uber or Lyft — and people are paying anyway

June 14, 2025
1.3k
Load More
Next Post
Smartphone

Google Maps is giving your ETA screen a glow-up on Android

Intuit QuickBooks Desktop Pro Plus 2024 (1 User) for Windows: Lifetime License for $249

Intuit QuickBooks Desktop Pro Plus 2024 (1 User) for Windows: Lifetime License for $249

SMOOTHIE TOYS Drinks Food MAKER Wood Toy Blender Pretend Fruit Funny Kitten Playset

SMOOTHIE TOYS Drinks Food MAKER Wood Toy Blender Pretend Fruit Funny Kitten Playset

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Tech Resources

  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo
  • Google News
  • Hacker News
  • Harvard Tech
  • I Like Cats ™
  • I Like Dogs ™
  • LifeHacker
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • PC World
  • Photofocus
  • Physics
  • Random Tech
  • Retro Rewind ™
  • Robot Report
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Art
  • Tech Careers
  • Tech Deals
  • Techcratic ™
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Tech News

  • 30 Second Tech ™
  • AI
  • Apple Insider
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • ExtremeTech
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo

Tech News

  • Harvard Tech
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • Physics
  • PC World
  • Random Tech
  • Retro Rewind ™
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Careers

Tech News​

  • Tech Art
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Site Links

  • About Techcratic
  • Affiliate Disclaimer
  • Affiliate Link Policy
  • Contact Techcratic
  • Dealors Discount Store
  • Privacy and Security Disclaimer
  • Privacy Policy
  • RSS Feed
  • Site Map
  • Support Techcratic
  • Techcratic
  • Tech Deals
  • TOS
  • 𝕏
Click For A Secret Deal

Techcratic – Your All In One Tech Hub © 2020 – 2025
All Rights Reserved
∞

No Result
View All Result
  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Gaming
  • I Like Cats ™
  • I Like Dogs ™
  • MacRumors
  • Macworld
  • Tech Deals
  • Techcratic ™
  • Techs Got To Eat ™
  • Tesla
  • UFO
  • Wired