grub-btrfs through 2026-01-31 (as packaged on Arch Linux and derivative distributions) contains an OS command injection flaw in the initramfs/early-boot context due to improper sanitization of the $root parameter passed to resolve_device(). A crafted $root value can be interpreted in a way that results in execution of attacker-controlled shell commands when resolve_device() processes it. A third-party note indicates exploitation may not be feasible under normal conditions and may depend on specific implementation details within resolve_device().
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Bash proof-of-concept and a simple detection script for CVE-2026-25828, a command-injection issue in Arch Linux's grub-btrfs initramfs hook (grub-btrfs-overlayfs). The core idea is that the initramfs hook uses the kernel command-line parameter $root without sanitization when calling resolve_device(), allowing shell metacharacters in root= to break out and execute arbitrary commands as root during early boot. Structure and purpose: - CVE-2026-25828-poc.sh: Not an automated exploit; it prints step-by-step instructions to exploit by editing the GRUB boot entry (press 'e') and injecting a command into root="/dev/sda1; YOUR_COMMAND; #". - README.md: Detailed vulnerability write-up, affected component path (/etc/initcpio/hooks/grub-btrfs-overlayfs), vulnerable code snippet, and multiple attack scenarios (physical GRUB edit, PXE boot manipulation, malicious GRUB config). Includes example payloads such as modifying /etc/passwd, downloading remote scripts, and a reverse shell to 192.168.1.100:4444. - detection.sh: A local checker that greps the hook file for a pattern suggesting resolve_device is called with $root, printing VULNERABLE/Not vulnerable. Capabilities: - Achieves arbitrary command execution as root at initramfs/boot time when an attacker can influence the kernel command line (local console/GRUB, GRUB config tampering, or PXE/DHCP/TFTP control). No direct network exploitation code is included; network endpoints in the README are illustrative examples of payload delivery/callbacks.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.