← console
voxell vciy

CVE-2025-54771: Grub2: use-after-free in grub_file_close()

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. No fix version is held. The CNA's first reference is the place to look: access.redhat.com
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded.

weakness
CWE-825 Expired Pointer Dereference
affected
GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4
versions
GNU grub2 <= 2.14
fixed in
No fix version in held sources.
severity
4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
assigned by
redhat
published
2025-11-18

check us access.redhat.com bugzilla.redhat.com lists.gnu.org

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
19 Nov 20250.00012
24 Nov 20250.00016
20 Dec 20250.00017
25 Jan 20260.00018
20 Mar 20260.00029
16 Apr 20260.00015
17 Apr 20260.00014
28 Apr 20260.00017
20 May 20260.00019
14 Jun 20260.00022
15 Jun 20260.00125scoring model v2026.06.15
17 Jun 20260.00127
7 Jul 20260.0013
16 Jul 20260.00144
14 Aug 20260.00147
28 Sep 20260.00142

16 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.00 on 2026-09-28 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
No fix version is held. One published by the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2025-54771', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.