Grub2 — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 20, 2025
Last Seen
June 18, 2026

Related Threat Clusters

  • Critical UEFI Secure Boot Bypass Vulnerability Discovered

    ESET researchers identified a significant vulnerability, CVE-2024-7344, allowing bypass of UEFI Secure Boot on numerous systems. This flaw affects UEFI applications signed by multiple vendors, enabling attackers to…

    4 articles · Updated June 18, 2026
  • Multiple Vulnerabilities Found in grub2 Affecting Data Integrity and Availability

    Two vulnerabilities, CVE-2021-20225 and CVE-2021-20233, were discovered in grub2 versions prior to 2.06. CVE-2021-20225 allows attackers to write past the end of a heap, while CVE-2021-20233 enables memory corruption…

    2 articles · Updated February 26, 2026
  • SUSE and openSUSE Address Moderate grub2 Vulnerabilities

    SUSE and openSUSE have released updates for grub2 to address multiple vulnerabilities, including use-after-free and out-of-bounds write issues. The updates fix specific CVEs, including CVE-2025-54771 and CVE-2025-61661,…

    46 articles · Updated November 20, 2025
  • SUSE and openSUSE Address Multiple grub2 Vulnerabilities

    SUSE and openSUSE have released updates for grub2 to address several vulnerabilities, including use-after-free and out-of-bounds write issues. The vulnerabilities, identified by CVE-2025-54771, CVE-2025-61661,…

    2 articles · Updated November 21, 2025
  • SUSE and openSUSE Address Multiple grub2 Vulnerabilities

    SUSE and openSUSE have released updates for the grub2 bootloader to address several vulnerabilities, including use-after-free issues and an out-of-bounds write. The vulnerabilities, identified by CVE-2025-54771,…

    6 articles · Updated November 28, 2025
  • Multiple Grub2 Vulnerabilities Discovered Leading to Use-After-Free Issues

    Three vulnerabilities in Grub2 have been identified, each related to a missing unregister call for different commands: normal commands (CVE-2025-61663), normal_exit commands (CVE-2025-61664), and gettext commands…

    3 articles · Updated December 13, 2025

Recent Intelligence Reports

  • Under Cloak Uefi Secure Boot Introducing Cve 2024 7344 — www.welivesecurity.com · June 18, 2026
  • CVE-2021-20225 A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap — Api.Msrc.Microsoft · February 26, 2026
  • CVE-2025-61664 Grub2: missing unregister call for normal_exit command may lead to use-after — Api.Msrc.Microsoft · December 13, 2025
  • CVE-2025-61663 Grub2: missing unregister call for normal commands may lead to use-after — Api.Msrc.Microsoft · December 13, 2025
  • SUSE: Grub2 Moderate Update 2025:4224-1 CVE-2025-54771 CVE-2025 — Linuxsecurity · November 25, 2025
  • SUSE: Grub2 Moderate Advisory 2025:4152-1 for Use-After — Linuxsecurity · November 21, 2025
  • SUSE: grub2 Moderate Use-After-Free Flaws SUSE-SU-2025:4143 — Linuxsecurity · November 20, 2025

CVSS v3.1 Breakdown