Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w9h-j8xp-j97v

Опубликовано: 18 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.

EPSS

Процентиль: 3%
0.00017
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-825

Связанные уязвимости

CVSS3: 4.9
ubuntu
28 дней назад

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.

CVSS3: 4.9
nvd
28 дней назад

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity.

CVSS3: 4.9
msrc
25 дней назад

Grub2: missing unregister call for normal_exit command may lead to use-after-free

CVSS3: 4.9
debian
28 дней назад

A vulnerability in the GRUB2 bootloader has been identified in the nor ...

CVSS3: 4.9
fstec
28 дней назад

Уязвимость функции normal_exit() загрузчика операционных систем Grub2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00017
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-825