CVE Database
/

CVE-2025-61662

Back to search

CVE-2025-61662

Published: Nov 18, 2025

Modified: May 20, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application to access a memory location that is no longer valid. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.

VendorProductVersions

GNU

grub2

affected
0 - <= 2.14

Red Hat

Red Hat Enterprise Linux 10

unaffected
1:2.12-29.el10_1.2 - < *

Red Hat

Red Hat Enterprise Linux 10.0 Extended Update Support

unaffected
1:2.12-15.el10_0.2 - < *

Red Hat

Red Hat Enterprise Linux 7 Extended Lifecycle Support

unaffected
1:2.02-0.87.el7_9.16 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
1:2.02-170.el8_10.1 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
1:2.02-87.el8_2.14 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
1:2.02-99.el8_4.13 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

unaffected
1:2.02-99.el8_4.13 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
1:2.02-123.el8_6.19 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
1:2.02-123.el8_6.19 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
1:2.02-123.el8_6.19 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Telecommunications Update Service

unaffected
1:2.02-152.el8_8.3 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

unaffected
1:2.02-152.el8_8.3 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
1:2.06-114.el9_7.1 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

unaffected
1:2.06-27.el9_0.23 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

unaffected
1:2.06-61.el9_2.11 - < *

Red Hat

Red Hat Enterprise Linux 9.4 Extended Update Support

unaffected
1:2.06-86.el9_4.4 - < *

Red Hat

Red Hat Enterprise Linux 9.6 Extended Update Support

unaffected
1:2.06-105.el9_6.1 - < *

Red Hat

Red Hat OpenShift Container Platform 4.12

unaffected
412.86.202604010116-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.13

unaffected
413.92.202604080111-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
414.92.202605060243-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.15

unaffected
415.92.202605060220-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
416.94.202604211449-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
417.94.202605112123-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.18

unaffected
418.94.202603181125-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.19

unaffected
4.19.9.6.202604080618-0 - < *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

RHSA-2026:10097
vendor-advisory
x_refsource_REDHAT
RHSA-2026:14773
vendor-advisory
x_refsource_REDHAT
RHSA-2026:15087
vendor-advisory
x_refsource_REDHAT
RHSA-2026:17596
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4648
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4649
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4652
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4653
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4654
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4760
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4822
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4823
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4830
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4900
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4998
vendor-advisory
x_refsource_REDHAT
RHSA-2026:5074
vendor-advisory
x_refsource_REDHAT
RHSA-2026:5127
vendor-advisory
x_refsource_REDHAT
RHSA-2026:5233
vendor-advisory
x_refsource_REDHAT
RHSA-2026:6492
vendor-advisory
x_refsource_REDHAT
RHSA-2026:7239
vendor-advisory
x_refsource_REDHAT
RHSA-2026:7243
vendor-advisory
x_refsource_REDHAT
RHBZ#2414683
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now