PT-2020-3312 · Gnu+8 · Grub2+8

Jesse Michael

+1

·

Published

2020-07-29

·

Updated

2025-08-02

·

CVE-2020-10713

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GRUB2 versions prior to 2.06
Description A flaw was found in GRUB2 that allows an attacker to hijack and tamper with the GRUB verification process, bypassing Secure Boot protections. This can be exploited to load an untrusted or modified kernel, potentially leading to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. An attacker would first need to establish access to the system, such as gaining physical access or obtaining remote access to a networked system with root access. With this access, an attacker could craft a string to cause a buffer overflow by injecting a malicious payload.
Recommendations To resolve the issue for GRUB2 versions prior to 2.06, update to version 2.06 or later. As a temporary workaround, consider restricting access to the GRUB configuration file to minimize the risk of exploitation. Additionally, ensure that Secure Boot is enabled and properly configured to reduce the risk of malicious code execution.

Exploit

Fix

Buffer Overflow

Memory Corruption

OS Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3534
ALT-PU-2021-1969
ALT-PU-2021-3464
AZL-6455
BDU:2020-03625
CESA-2020_3216
CESA-2020_3217
CVE-2020-10713
DSA-4735-1
DSA-4735-2
MGASA-2021-0315
OPENSUSE-SU-2020:1168-1
OPENSUSE-SU-2020:1169-1
OPENSUSE-SU-2020_1168-1
OPENSUSE-SU-2020_1169-1
OPENSUSE-SU-2024:10824-1
RHSA-2020:3216
RHSA-2020:3217
RHSA-2020:3223
RHSA-2020:3227
RHSA-2020:3271
RHSA-2020:3273
RHSA-2020:3274
RHSA-2020:3275
RHSA-2020:3276
RHSA-2020:4115
RHSA-2020:4172
RHSA-2020_3216
RHSA-2020_3217
SUSE-SU-2020:14440-1
SUSE-SU-2020:14490-1
SUSE-SU-2020:2073-1
SUSE-SU-2020:2074-1
SUSE-SU-2020:2076-1
SUSE-SU-2020:2077-1
SUSE-SU-2020:2078-1
SUSE-SU-2020:2079-1
SUSE-SU-2020:2626-1
SUSE-SU-2020:2627-1
SUSE-SU-2020:2628-1
SUSE-SU-2020:2629-1
SUSE-SU-2020_14440-1
SUSE-SU-2020_14490-1
SUSE-SU-2020_2073-1
SUSE-SU-2020_2074-1
SUSE-SU-2020_2076-1
SUSE-SU-2020_2077-1
SUSE-SU-2020_2078-1
SUSE-SU-2020_2079-1
SUSE-SU-2020_2626-1
SUSE-SU-2020_2627-1
SUSE-SU-2020_2628-1
SUSE-SU-2020_2629-1
USN-4432-1
USN-4432-2

Affected Products

Alt Linux
Centos
Grub2
Huawei Vrp
Linuxmint
Red Hat
Red Os
Suse
Ubuntu