Vulnerability Description
grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device."
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://archlinux.org/packages/extra/any/grub-btrfs/
- https://github.com/Antynea/grub-btrfs/tree/master
- https://github.com/cardosource/CVE-2026-25828
FAQ
What is CVE-2026-25828?
CVE-2026-25828 is a vulnerability with a CVSS score of 5.4 (MEDIUM). grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third par...
How severe is CVE-2026-25828?
CVE-2026-25828 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25828?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.