CVE-2026-25828

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device."
Configurations

No configuration.

History

04 Mar 2026, 08:16

Type Values Removed Values Added
Summary
  • (es) grub-btrfs hasta el 31-01-2026 (en Arch Linux y distribuciones derivadas) permite la inyección de comandos del sistema operativo en initramfs porque no sanea el parámetro $root de resolve_device().
Summary (en) grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). (en) grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device."

13 Feb 2026, 21:16

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

12 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 22:16

Updated : 2026-04-15 00:35


NVD link : CVE-2026-25828

Mitre link : CVE-2026-25828

CVE.ORG link : CVE-2026-25828


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')