GNU Vulnerabilities and Affected Products
Vulnerabilities associated with grub2.
Products
Clear product- Binutils31 vulnerabilities
- grub213 vulnerabilities
- LibreDWG11 vulnerabilities
- PSPP8 vulnerabilities
- elfutils6 vulnerabilities
- Emacs6 vulnerabilities
- Bourne-Again Shell (Bash)5 vulnerabilities
- inetutils5 vulnerabilities
- gawk4 vulnerabilities
- gdb4 vulnerabilities
- cflow3 vulnerabilities
- cpio3 vulnerabilities
- glibc3 vulnerabilities
- GNU C Library (glibc)3 vulnerabilities
- GNU SASL3 vulnerabilities
- Mailman3 vulnerabilities
- Bison2 vulnerabilities
- coreutils2 vulnerabilities
- GCC2 vulnerabilities
- GnuPG2 vulnerabilities
- Guix2 vulnerabilities
- gzip2 vulnerabilities
- Libgcrypt2 vulnerabilities
- ncurses2 vulnerabilities
- patch2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-4631CRITICAL | Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injectionCockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning … | CVSS9.8v3.1 | EPSS15.5% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-54770MEDIUM | Grub2: use-after-free in net_set_vlanA vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from memory. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash … CWE-825Nov 18, 2025 | CVSS4.9v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61664MEDIUM | Grub2: missing unregister call for normal_exit command may lead to use-after-freeA vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity. CWE-825Nov 18, 2025 | CVSS4.9v3.1 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61663MEDIUM | Grub2: missing unregister call for normal commands may lead to use-after-freeA vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the module is unloaded. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash and halt system availabili… CWE-825Nov 18, 2025 | CVSS4.9v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61662HIGH | Grub2: missing unregister call for gettext command may lead to use-after-freeA Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory location that is no longer valid. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality com… CWE-416Nov 18, 2025 | CVSS7.8v3.1 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61661MEDIUM | Grub2: grub2: out-of-bounds write via malicious usb deviceA vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although… CWE-131Nov 18, 2025 | CVSS4.8v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-54771MEDIUM | Grub2: use-after-free in grub_file_close()A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded. CWE-825Nov 18, 2025 | CVSS4.9v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-6019HIGH | Libblockdev: lpe from allow_active to root in libblockdev via udisksA Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. … CWE-250Jun 19, 2025 | CVSS7.0v3.1 | EPSS0.446% | PoCs26 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56737HIGH | GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem. CWE-122Dec 29, 2024 | CVSS8.8v3.1 | EPSS0.735% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-56738MEDIUM | GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks. | CVSS5.3v3.1 | EPSS0.413% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6409HIGH | Openssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 9A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running th… CWE-364Jul 8, 2024 | CVSS7.0v3.1 | EPSS27.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2312MEDIUM | GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass. CWE-416Apr 5, 2024 | CVSS6.7v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-10713HIGH | GNU grub2 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craf… CWE-120Jul 30, 2020 | CVSS8.2v3.1 | EPSS1.71% | PoCs1 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |