Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61661

Опубликовано: 18 нояб. 2025
Источник: redhat
CVSS3: 4.8

Описание

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.

Отчет

This vulnerability was rated as having the impact of Moderate by the Red Hat Product Security Engineering team. To exploit this flaw the attacker needs to have physical access to the machine and connect a maliciously crafted USB device which will leverage the lack of string size validation to cause a out-of-bounds write when reading strings from it. Even though the existence of a possible out-of-bounds write, given the complexity of producing the exploit, the impact is most likely limited to leading grub to crash causing a Denial-of-Service kind of attack or uncontrolled data corruption which presents a Low impact in the Integrity point of the CIA triad in the CVSS scoring.

Меры по смягчению последствий

As a mitigation Red Hat doesn't recommend to connect untrusted or unknown USB devices to the machine.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10grub2Fix deferred
Red Hat Enterprise Linux 7grub2Fix deferred
Red Hat Enterprise Linux 8grub2Fix deferred
Red Hat Enterprise Linux 9grub2Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2413827grub2: grub2: Out-of-bounds write via malicious USB device

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
4 месяца назад

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.

CVSS3: 4.8
nvd
4 месяца назад

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.

CVSS3: 4.8
msrc
4 месяца назад

Grub2: grub2: out-of-bounds write via malicious usb device

CVSS3: 4.8
debian
4 месяца назад

A vulnerability has been identified in the GRUB (Grand Unified Bootloa ...

CVSS3: 4.8
github
4 месяца назад

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.

4.8 Medium

CVSS3