Logo
vulnerabilityCVE-2025-61664
Name
CVE-2025-61664
Source
NVD ( link)Debian ( link)
Description
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
grub
Exploitable

Vulnerability Ratings#


4.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.12
Exploitable
buildroot
master
2.14
Exploitable
openwrt
master
2.12-r1
Exploitable
openwrt
openwrt-25.12
2.12-r1
Exploitable
yocto
kirkstone
2.06
Exploitable
yocto
scarthgap
2.12
Exploitable