PT-2020-12207 · Gnu · Grub2-Bhyve

Reno Robert

·

Published

2020-03-14

·

Updated

2021-07-21

·

CVE-2020-10565

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions grub2-bhyve versions prior to revision 525916 2020-02-12
Description The issue allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process, resulting in code execution as root on the host OS. This is due to the lack of validation of the address provided as part of a memrw command by a guest through a grub2.cfg file.
Recommendations For versions prior to revision 525916 2020-02-12, update to a version after revision 525916 2020-02-12 to resolve the issue. As a temporary workaround, consider restricting access to the grub2.cfg file to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10565

Affected Products

Grub2-Bhyve