CVE-2025-61664
published 2025-11-18CVE-2025-61664: A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit…
PriorityP427medium4.9CVSS 3.1
AVLACHPRNUINSUCLILAL
EPSS
0.14%
3.5th percentile
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.14-1 (sid) | grub2 2.14-1 (sid) |
| gnu | grub2 | <= 2.14 | — |
| msrc | azl3_grub2_2.06-25_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-26_on_azure_linux_3.0 | — | — |
| msrc | cbl2_grub2_2.06-15_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_msrc4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7w9h-j8xp-j97v: A vulnerability in the GRUB2 bootloader has been identified in the normal module
ghsa_unreviewed·2025-11-18
CVE-2025-61664 [MEDIUM] CWE-825 GHSA-7w9h-j8xp-j97v: A vulnerability in the GRUB2 bootloader has been identified in the normal module
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.
OSV
CVE-2025-61664: A vulnerability in the GRUB2 bootloader has been identified in the normal module
osv·2025-11-18·CVSS 4.9
CVE-2025-61664 [MEDIUM] CVE-2025-61664: A vulnerability in the GRUB2 bootloader has been identified in the normal module
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.
Red Hat
grub2: Missing unregister call for normal_exit command may lead to use-after-free
vendor_redhat·2025-11-18·CVSS 4.9
CVE-2025-61664 [MEDIUM] CWE-825 grub2: Missing unregister call for normal_exit command may lead to use-after-free
grub2: Missing unregister call for normal_exit command may lead to use-after-free
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unload
Microsoft
Grub2: missing unregister call for normal_exit command may lead to use-after-free
vendor_msrc·2025-11-11·CVSS 4.9
CVE-2025-61664 [MEDIUM] CWE-825 Grub2: missing unregister call for normal_exit command may lead to use-after-free
Grub2: missing unregister call for normal_exit command may lead to use-after-free
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-61664: grub2 - A vulnerability in the GRUB2 bootloader has been identified in the normal module...
vendor_debian·2025·CVSS 4.9
CVE-2025-61664 [MEDIUM] CVE-2025-61664: grub2 - A vulnerability in the GRUB2 bootloader has been identified in the normal module...
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2.14-1)
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published