CVE-2025-54771 Details
Description
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.
A use-after-free vulnerability has been identified in GNU GRUB. This issue arises because the file-closing process improperly manages memory pointers, leaving an invalid reference to a file system structure. An attacker could exploit this flaw to cause GRUB to crash, resulting in a denial-of-service condition. There are also potential concerns regarding data integrity or confidentiality.
Users can refer to the Red Hat Security Advisory for guidance on addressing this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 18, 2025CISA-ADP
Assessed Nov 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/11/18/3 | CVE | Mailing ListTechnical Description |
| https://access.redhat.com/security/cve/CVE-2025-54771 | [email protected] | AdvisoryVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2413823 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://lists.gnu.org/archive/html/grub-devel/2025-11/msg00155.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-825 | Expired Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GNU GRUB | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux | All versions |
CPE
Remediation
| |
| Red Hat OpenShift Container Platform | All versions |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| Nov 18, 2025 | CVE Modified | CVE |
| Nov 18, 2025 | New CVE Received | [email protected] |
Volerion