CVE-2025-54771
published 2025-11-18CVE-2025-54771: A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly…
PriorityP424medium4.9CVSS 3.1
AVLACHPRNUINSUCLILAL
EPSS
0.14%
4.1th percentile
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.14-1 (sid) | grub2 2.14-1 (sid) |
| gnu | grub2 | <= 2.14 | — |
| msrc | azl3_grub2_2.06-25_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06-15_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_msrc4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grub2: Use-after-free in grub_file_close()
vendor_redhat·2025-11-18·CVSS 4.9
CVE-2025-54771 [MEDIUM] CWE-825 grub2: Use-after-free in grub_file_close()
grub2: Use-after-free in grub_file_close()
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Pos
Microsoft
Grub2: use-after-free in grub_file_close()
vendor_msrc·2025-11-11·CVSS 4.9
CVE-2025-54771 [MEDIUM] CWE-825 Grub2: use-after-free in grub_file_close()
Grub2: use-after-free in grub_file_close()
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2025-54771: grub2 - A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unifie...
vendor_debian·2025·CVSS 4.9
CVE-2025-54771 [MEDIUM] CVE-2025-54771: grub2 - A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unifie...
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2.14-1)
trixie: open
GHSA
GHSA-5rr4-3f6q-m7hp: A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader)
ghsa_unreviewed·2025-11-18
CVE-2025-54771 [MEDIUM] CWE-825 GHSA-5rr4-3f6q-m7hp: A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader)
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
OSV
CVE-2025-54771: A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader)
osv·2025-11-18·CVSS 4.9
CVE-2025-54771 [MEDIUM] CVE-2025-54771: A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader)
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published