CVE-2025-61661
published 2025-11-18CVE-2025-61661: A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when…
PriorityP418medium4.8CVSS 3.1
AVPACHPRNUINSUCNILAH
EPSS
0.19%
8.8th percentile
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.14-1 (sid) | grub2 2.14-1 (sid) |
| gnu | grub2 | <= 2.14 | — |
| msrc | azl3_grub2_2.06-25_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-26_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grub2_2.06-16_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
osv4.8MEDIUM
vendor_debian4.8MEDIUM
vendor_msrc4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grub2: grub2: Out-of-bounds write via malicious USB device
vendor_redhat·2025-11-18·CVSS 4.8
CVE-2025-61661 [MEDIUM] CWE-131 grub2: grub2: Out-of-bounds write via malicious USB device
grub2: grub2: Out-of-bounds write via malicious USB device
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading
Microsoft
Grub2: grub2: out-of-bounds write via malicious usb device
vendor_msrc·2025-11-11·CVSS 4.8
CVE-2025-61661 [MEDIUM] CWE-131 Grub2: grub2: out-of-bounds write via malicious usb device
Grub2: grub2: out-of-bounds write via malicious usb device
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-61661: grub2 - A vulnerability has been identified in the GRUB (Grand Unified Bootloader) compo...
vendor_debian·2025·CVSS 4.8
CVE-2025-61661 [MEDIUM] CVE-2025-61661: grub2 - A vulnerability has been identified in the GRUB (Grand Unified Bootloader) compo...
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2.14-1)
trixie: open
GHSA
GHSA-cjch-253g-8hp2: A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component
ghsa_unreviewed·2025-11-18
CVE-2025-61661 [MEDIUM] CWE-131 GHSA-cjch-253g-8hp2: A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
OSV
CVE-2025-61661: A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component
osv·2025-11-18·CVSS 4.8
CVE-2025-61661 [MEDIUM] CVE-2025-61661: A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published