Use-After-Free Vulnerability in GRUB's gettext Module by Red Hat
CVE-2025-61662

4.9MEDIUM

What is CVE-2025-61662?

A Use-After-Free vulnerability in the gettext module of GRUB has been identified, resulting from a programming flaw that allows the gettext command to persist in memory after its module has been unloaded. This vulnerability can be exploited by an attacker to invoke the orphaned command, leading to access of invalid memory locations. Such exploitation can result in application crashes, potentially resulting in Denial of Service conditions. While direct data compromise is not guaranteed, the integrity and confidentiality of the system may still be at risk due to the instability introduced by this flaw.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61662 : Use-After-Free Vulnerability in GRUB's gettext Module by Red Hat