PT-2026-7909 · Unknown · Grub-Btrfs

Cardosource

·

Published

2026-02-12

·

Updated

2026-03-04

·

CVE-2026-25828

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions grub-btrfs versions through 2026-01-31
Description The software does not properly sanitize the root parameter when resolving devices, leading to potential command injection within the initramfs environment. This could allow for unauthorized execution of operating system commands.
Recommendations Update grub-btrfs to a version newer than 2026-01-31.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-25828

Affected Products

Grub-Btrfs