Use-After-Free Vulnerability in GNU GRUB by Red Hat
CVE-2025-54771

4.9MEDIUM

What is CVE-2025-54771?

A use-after-free vulnerability has been detected in the GNU GRUB (Grand Unified Bootloader). This issue arises due to an error in the file-closing procedure, which incorrectly maintains a memory pointer, creating an invalid reference to a file system structure. An attacker may exploit this flaw to trigger a crash in GRUB, resulting in a Denial of Service. Additionally, there are concerns about potential impacts on data integrity and confidentiality.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54771 : Use-After-Free Vulnerability in GNU GRUB by Red Hat