{"id":"CVE-2025-4002","summary":"RefindPlusRepo RefindPlus BootLog.c GetDebugLogFile null pointer dereference","details":"A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue is the function GetDebugLogFile of the file Library/MemLogLib/BootLog.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The patch is identified as d2143a1e2deefddd9b105fb7160763c4f8d47ea2. It is recommended to apply a patch to fix this issue.","modified":"2026-08-12T15:16:30.559473Z","published":"2025-04-28T05:00:07.032Z","database_specific":{"cwe_ids":["CWE-404","CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4002.json","cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4002.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4002"},{"type":"ADVISORY","url":"https://vuldb.com/?id.306338"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.558122"},{"type":"REPORT","url":"https://github.com/RefindPlusRepo/RefindPlus/issues/204"},{"type":"REPORT","url":"https://github.com/RefindPlusRepo/RefindPlus/issues/204#issuecomment-2696817643"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.306338"},{"type":"FIX","url":"https://github.com/RefindPlusRepo/RefindPlus/commit/d2143a1e2deefddd9b105fb7160763c4f8d47ea2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/refindplusrepo/refindplus","events":[{"introduced":"1b22ff94225f3c477a5ddc79997a1d69dfc347c2"},{"fixed":"d2143a1e2deefddd9b105fb7160763c4f8d47ea2"}],"database_specific":{"extracted_events":[{"introduced":"0.14.2.AB"},{"last_affected":"0.14.2.AB"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.14.2.AB"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4002.json","vanir_signatures_modified":"2026-08-12T15:16:30Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/refindplusrepo/refindplus/commit/d2143a1e2deefddd9b105fb7160763c4f8d47ea2","target":{"file":"Library/MemLogLib/BootLog.c","function":"GetDebugLogFile"},"deprecated":false,"digest":{"function_hash":"329880505637215782182931889380913516842","length":623},"id":"CVE-2025-4002-72a4832e","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/refindplusrepo/refindplus/commit/d2143a1e2deefddd9b105fb7160763c4f8d47ea2","target":{"file":"Library/MemLogLib/BootLog.c"},"deprecated":false,"digest":{"line_hashes":["191921237139586538236307394299950485894","84210818516765533741133200819114377089","127263316154263755031786260639975186863","148862171365641641891914714875277448587","91402055683624337001456373463015599966","334287097222878907213810807709816207479","189041496169917525893429877194637249709","300426660898589698659240634375435260026","28599016512008765235353853924541528336","88702490114482450609164787348443581262","297371870804072000769745160484342925270"],"threshold":0.9},"id":"CVE-2025-4002-fbb0b0ae"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}