CVE-2025-61664

MEDIUM

GRUB2 - Use After Free

Title source: llm

Description

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.

Scores

CVSS v3 4.9
EPSS 0.0002
EPSS Percentile 4.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-825
Status draft

Timeline

Published Nov 18, 2025
Tracked Since Feb 18, 2026