No analysis available yet.
Vendor Workaround
As a mitigation Red Hat doesn't recommend to connect untrusted or unknown USB devices to the machine.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Grub2: out-of-bounds write | Grub2: grub2: out-of-bounds write via malicious usb device |
Wed, 19 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 18 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 18 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited. | |
| Title | Grub2: out-of-bounds write | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-131 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-12-19T16:33:49.048Z
Reserved: 2025-09-29T20:18:48.974Z
Link: CVE-2025-61661
Updated: 2025-11-18T22:03:42.773Z
Status : Deferred
Published: 2025-11-18T19:15:49.973
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-61661
OpenCVE Enrichment
No data.