grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device."
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-02-12 22:16
Updated : 2026-03-04 08:16
NVD link : CVE-2026-25828
Mitre link : CVE-2026-25828
CVE.ORG link : CVE-2026-25828
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
