cbcvebase.
CVE-2025-61662
published 2025-11-18

CVE-2025-61662: A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains…

PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
10.9th percentile
A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory location that is no longer valid. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangrub2< grub2 2.14-1 (sid)grub2 2.14-1 (sid)
gnugrub2<= 2.14
msrcazl3_grub2_2.06-25_on_azure_linux_3.0
msrcazl3_grub2_2.06-26_on_azure_linux_3.0
msrccbl2_grub2_2.06-15_on_cbl_mariner_2.0
msrccbl2_grub2_2.06-16_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.