Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61662

29
FAUCET Score

CVE-2025-61662 is a Use-After-Free vulnerability in GRUB's gettext module, affecting gnu grub2. This flaw occurs when the gettext command remains in memory after its module is unloaded, allowing an attacker to trigger a crash by invoking the orphaned command. Rated 7.8 HIGH on CVSS, this vulnerability has a low attack complexity and requires local privileges, potentially leading to a Denial of Service and possible data integrity or confidentiality compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with its EPSS and FAUCET Risk Score indicating a relatively low immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.14CPE matchmatch criteria
cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 39th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia msrc
Product: azl3 grub2 2.06-26 on Azure Linux 3.0Fixed in: 2.06-26
microsoftpatch availablevia msrc
Product: 20560-17084Fixed in: 2.06-26
microsoftpatch availablevia msrc
Product: 20796-17084Fixed in: 2.06-26
microsoftpatch availablevia msrc
Product: cbl2 grub2 2.06-15 on CBL Mariner 2.0Fixed in: 2.06-16
microsoftpatch availablevia msrc
Product: cbl2 grub2 2.06-16 on CBL Mariner 2.0Fixed in: 2.06-16
microsoftpatch availablevia msrc
Product: azl3 grub2 2.06-25 on Azure Linux 3.0Fixed in: 2.06-26
microsoftpatch availablevia msrc
Product: 20521-17086Fixed in: 2.06-16
microsoftpatch availablevia msrc
Product: 20771-17086Fixed in: 2.06-16
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: grub2
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grub2
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grub2
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: grub2

Vendor Advisories (2)

redhatCVE-2025-61662Moderate

grub2: Missing unregister call for gettext command may lead to use-after-free

Nov 18, 2025
microsoft2025-Nov/CVE-2025-61662Moderate

Grub2: missing unregister call for gettext command may lead to use-after-free

Nov 11, 2025

References

openwall.com / lists/oss-security/2025/11/18/5
Mailing ListPatch
access.redhat.com / errata/RHSA-2026:10097
access.redhat.com / errata/RHSA-2026:14773
access.redhat.com / errata/RHSA-2026:15087
access.redhat.com / errata/RHSA-2026:17596
access.redhat.com / errata/RHSA-2026:4648
access.redhat.com / errata/RHSA-2026:4649
access.redhat.com / errata/RHSA-2026:4652
access.redhat.com / errata/RHSA-2026:4653
access.redhat.com / errata/RHSA-2026:4654
access.redhat.com / errata/RHSA-2026:4760
access.redhat.com / errata/RHSA-2026:4822
access.redhat.com / errata/RHSA-2026:4823
access.redhat.com / errata/RHSA-2026:4830
access.redhat.com / errata/RHSA-2026:4900
access.redhat.com / errata/RHSA-2026:4998
access.redhat.com / errata/RHSA-2026:5074
access.redhat.com / errata/RHSA-2026:5127
access.redhat.com / errata/RHSA-2026:5233
access.redhat.com / errata/RHSA-2026:6492
access.redhat.com / errata/RHSA-2026:7239
access.redhat.com / errata/RHSA-2026:7243
access.redhat.com / security/cve/CVE-2025-61662
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
lists.gnu.org / archive/html/grub-devel/2025-11/msg00155.html