
CVE-2026-25828 grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to r… https://www.cve.org/CVERecord?id=CVE-2026-25828
Post summary
CVE-2026-25828 is a vulnerability in grub-btrfs that permits OS command injection in the initramfs due to an unsanitized $root parameter, impacting Arch Linux and derivative distributions.

