Logo
vulnerabilityCVE-2025-61662
Name
CVE-2025-61662
Source
NVD ( link)Debian ( link)
Description
A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory location that is no longer valid. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
grub
Exploitable

Vulnerability Ratings#


7.8
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.12
Exploitable
buildroot
master
2.14
Exploitable
openwrt
master
2.12-r1
Exploitable
openwrt
openwrt-25.12
2.12-r1
Exploitable
yocto
kirkstone
2.06
Exploitable
yocto
scarthgap
2.12
Exploitable