Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsanitized $root Parameter in grub-btrfs Enables Initramfs Command Injection |
Wed, 04 Mar 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). | grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device." |
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Antynea
Antynea grub-btrfs |
|
| Vendors & Products |
Antynea
Antynea grub-btrfs |
Fri, 13 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
Thu, 12 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-04T07:56:41.457Z
Reserved: 2026-02-06T00:00:00.000Z
Link: CVE-2026-25828
Updated: 2026-02-13T20:54:03.096Z
Status : Deferred
Published: 2026-02-12T22:16:05.493
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-25828
No data.
OpenCVE Enrichment
Updated: 2026-04-16T17:15:17Z