CVE-2026-25828Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device."

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-15: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-15: 102-1202-15
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-121
Disclosure1
2026-02-151
Patch1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25828 grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to r… https://www.cve.org/CVERecord?id=CVE-2026-25828

    Post summary

    CVE-2026-25828 is a vulnerability in grub-btrfs that permits OS command injection in the initramfs due to an unsanitized $root parameter, impacting Arch Linux and derivative distributions.

    00020449
    56.5K followersView on X
  • Cybersecurity Aide@SecAideInfo
    Patch

    🚨 Alert: CVE-2026-25828 spotted! High risk of exploitation in grub-btrfs on Arch Linux & derivatives. ⚠️ Unsanitized $root in resolve_device() enables OS command injection via initramfs. Patch ASAP to stay safe! 🔒 #CyberSecurity #Linux #InfoSec

    Post summary

    The tweet announces CVE-2026-25828, details a command injection vulnerability in grub-btrfs on Arch Linux, and urges users to apply a patch immediately.

    0000053
    20 followersView on X

Explore more