CVE-2025-54770
Description
A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from memory. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash and halt system availability
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | affected | |
| debian | bullseye | affected | |
| debian | forky | fixed | 2.14-1 |
| debian | sid | fixed | 2.14-1 |
| debian | trixie | affected | |
| sles | affected | |
References
- https://access.redhat.com/security/cve/CVE-2025-54770
- https://bugzilla.redhat.com/show_bug.cgi?id=2413813
- https://lists.gnu.org/archive/html/grub-devel/2025-11/msg00155.html
- http://www.openwall.com/lists/oss-security/2025/11/18/4
- https://security-tracker.debian.org/tracker/CVE-2025-54770
- https://www.suse.com/security/cve/CVE-2025-54770.html
CWEs
CWE-825
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.