cbcvebase.
CVE-2025-61661
published 2025-11-18

CVE-2025-61661: A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when…

PriorityP418medium4.8CVSS 3.1
AVPACHPRNUINSUCNILAH
EPSS
0.19%
8.8th percentile
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangrub2< grub2 2.14-1 (sid)grub2 2.14-1 (sid)
gnugrub2<= 2.14
msrcazl3_grub2_2.06-25_on_azure_linux_3.0
msrcazl3_grub2_2.06-26_on_azure_linux_3.0
msrccbl2_grub2_2.06-15_on_cbl_mariner_2.0
msrccbl2_grub2_2.06-16_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.8MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
osv4.8MEDIUM
vendor_debian4.8MEDIUM
vendor_msrc4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.