Use-After-Free Vulnerability in GNU GRUB by Red Hat
CVE-2025-54771
4.9MEDIUM
What is CVE-2025-54771?
A use-after-free vulnerability has been detected in the GNU GRUB (Grand Unified Bootloader). This issue arises due to an error in the file-closing procedure, which incorrectly maintains a memory pointer, creating an invalid reference to a file system structure. An attacker may exploit this flaw to trigger a crash in GRUB, resulting in a Denial of Service. Additionally, there are concerns about potential impacts on data integrity and confidentiality.
Affected Version(s)
grub2 0 <= 2.14
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved