The GRUB bootloader that loads and starts the Linux kernel when the node powers on.
Version: 2.14
Type: CLI
License:
| Expand | CVE | Title | Status | |
|---|---|---|---|---|
| CVE-2025-61662 Open CVE-2025-61662 in a new tab | A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory location that is no longer valid. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded. | Not affected | High | |
| CVE-2024-56738 Open CVE-2024-56738 in a new tab | GNU GRUB (aka GRUB2) through 2. | Not affected | Unknown | |
| CVE-2025-4382 Open CVE-2025-4382 in a new tab | Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm | Not affected | Unknown | |
| CVE-2025-54770 Open CVE-2025-54770 in a new tab | Grub2: use-after-free in net_set_vlan | Not affected | Unknown | |
| CVE-2025-54771 Open CVE-2025-54771 in a new tab | Grub2: use-after-free in grub_file_close() | Not affected | Unknown | |
| CVE-2025-61661 Open CVE-2025-61661 in a new tab | Grub2: grub2: out-of-bounds write via malicious usb device | Not affected | Unknown | |
| CVE-2025-61663 Open CVE-2025-61663 in a new tab | Grub2: missing unregister call for normal commands may lead to use-after-free | Not affected | Unknown | |
| CVE-2025-61664 Open CVE-2025-61664 in a new tab | Grub2: missing unregister call for normal_exit command may lead to use-after-free | Not affected | Unknown |
A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory location that is no longer valid. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
GNU GRUB (aka GRUB2) through 2.
Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm
Grub2: use-after-free in net_set_vlan
Grub2: use-after-free in grub_file_close()
Grub2: grub2: out-of-bounds write via malicious usb device
Grub2: missing unregister call for normal commands may lead to use-after-free
Grub2: missing unregister call for normal_exit command may lead to use-after-free