Executive brief
A vulnerability in the GRUB bootloader, which is used to start many Linux-based operating systems, could allow an attacker with physical access to crash a system. By plugging in a specially crafted USB device during the boot process, an attacker can trigger a memory error that causes the computer to stop responding or potentially corrupt data. This issue primarily impacts system availability during the startup phase.
Technical details
A heap-based buffer overflow exists in GRUB2's 'grub_usb_get_string()' function within 'grub-core/commands/usbtest.c'. The vulnerability is caused by a time-of-check to time-of-use (TOCTOU) style inconsistency where the bootloader uses an initial length value from a USB descriptor for memory allocation, but subsequently uses a different length value from a second read during the UTF-16 to UTF-8 conversion. A local, physical attacker can connect a malicious USB device that provides inconsistent length descriptors to trigger an out-of-bounds write. This can result in a system crash (Denial of Service) or potentially limited data corruption. Patches have been developed to ensure the allocation and conversion use the same validated length field.
Affected products
- GNU Project GRUB2 All versions prior to November 2025 patches
Timeline
- 2025-11-10: other: Issue reported to Red Hat Bugzilla
- 2025-11-18: disclosed: Public disclosure and CVE assignment
- 2025-11-18: patched: Security patches submitted to GRUB development list