PT-2020-3624 · Gnu+7 · Grub2+7
Chris Coulson
·
Published
2020-07-29
·
Updated
2024-06-15
·
CVE-2020-15706
CVSS v3.1
6.4
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GRUB2 versions prior to 2.04
Description
The issue is related to a race condition in the
grub script function create() function of the Grub2 bootloader, which can lead to a use-after-free condition when a function is redefined while it is already executing. This can allow an attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability can also be exploited to achieve arbitrary code execution and bypass secure boot restrictions.Recommendations
For GRUB2 versions prior to 2.04, update to a version that includes the fix for this issue to prevent exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Grub2
Linuxmint
Red Hat
Red Os
Suse
Ubuntu