ThreatCluster

Multiple Grub2 Vulnerabilities Discovered Leading to Use-After-Free Issues

First seen 13 Dec 2025, 09:51 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Three vulnerabilities in Grub2 have been identified, each related to a missing unregister call for different commands: normal commands (CVE-2025-61663), normal_exit commands (CVE-2025-61664), and gettext commands (CVE-2025-61662). These vulnerabilities can lead to use-after-free conditions, potentially affecting systems utilizing Grub2 for boot management.