CVE-2025-61661
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
- EPSS probability
- 0.19%
- CWE
- CWE-131
- Published
- 2025-11-18
- Last modified
- 2026-09-01
Affected products
- GNU grub2
Weakness type
Related vulnerabilities
- CVE-2023-36824 — Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
- CVE-2024-23622 — IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow
- CVE-2024-23621 — IBM Merge Healthcare eFilm Workstation License Server Buffer Overflow
- CVE-2021-0254 — Junos OS: Remote code execution vulnerability in overlayd service
- CVE-2020-13585 — An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A spe
- CVE-2023-24819 — RIOT-OS vulnerable to Buffer Overflow during IPHC receive
- CVE-2022-22137 — A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci
- CVE-2021-21793 — An out-of-bounds write vulnerability exists in the JPG sof_nb_comp header processing functionality of Accusoft ImageGear