A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

As a mitigation Red Hat doesn't recommend to connect untrusted or unknown USB devices to the machine.

History

Wed, 19 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
Title Grub2: out-of-bounds write Grub2: grub2: out-of-bounds write via malicious usb device

Wed, 19 Nov 2025 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 18 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Tue, 18 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
Title Grub2: out-of-bounds write
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-131
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-19T20:14:18.041Z

Reserved: 2025-09-29T20:18:48.974Z

Link: CVE-2025-61661

cve-icon Vulnrichment

Updated: 2025-11-19T14:18:09.716Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-18T19:15:49.973

Modified: 2025-11-19T19:14:59.327

Link: CVE-2025-61661

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-11-18T00:00:00Z

Links: CVE-2025-61661 - Bugzilla

cve-icon OpenCVE Enrichment

No data.