CVE-2025-61661 Details
Description
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
A denial-of-service vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. The issue arises from improper string length handling when the bootloader reads data from a USB device. This flaw allows a local attacker to exploit the bootloader by connecting a maliciously configured USB device during the boot process. The exploitation can cause GRUB to crash, leading to a denial-of-service condition. Additionally, there is a potential for data corruption, although the complexity of the exploit suggests that any such impact would likely be limited.
Users can upgrade to a version of GRUB that includes the patch for this vulnerability. Red Hat users should consult the Red Hat Product Security team for guidance on available updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 18, 2025CISA-ADP
Assessed Nov 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/11/18/8 | CVE | Mailing ListTechnical Description |
| https://access.redhat.com/security/cve/CVE-2025-61661 | [email protected] | AdvisoryVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2413827 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-131 | Incorrect Calculation of Buffer Size | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GNU GRUB | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | CVE Modified | CVE |
| Nov 18, 2025 | New CVE Received | [email protected] |
Volerion