CVE-2026-25828 Details
Description
grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device."
A command injection vulnerability has been identified in the grub-btrfs package on Arch Linux and its derivatives, affecting all versions prior to January 31, 2026. The vulnerability arises in the initramfs hook 'grub-btrfs-overlayfs', which passes the '$root' parameter to the 'resolve_device()' function without proper sanitization. This oversight allows for arbitrary command execution as root during the early stages of the boot process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 12, 2026CISA-ADP
Assessed Feb 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://archlinux.org/packages/extra/any/grub-btrfs/ | [email protected] | ProductVendor |
| https://github.com/Antynea/grub-btrfs/tree/master | [email protected] | Source CodeVendor |
| https://github.com/cardosource/CVE-2026-25828 | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Antynea grub-btrfs | All versions |
CPE
Remediation
| |
| Arch Linux | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | CVE Modified | [email protected] |
| Feb 13, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | New CVE Received | [email protected] |
Volerion