← Back

CVE-2020-15706

nvd nist
Published: Jul 29, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.4
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD

Description

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

Affected (33)

Products: Gnu: Grub2 · Canonical: Ubuntu Linux · Debian: Debian Linux · +4 more
Show all products
1 product
Grub2
1 product
Ubuntu Linux
1 product
Debian Linux
3 products
Enterprise Linux
Enterprise Linux Atomic Host
Openshift Container Platform
1 product
Suse Linux Enterprise Server
6 products
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012
Windows Server 2016
Windows Server 2019
1 product
Leap
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.04
Configuration B
9 vulnerable
Configuration C
17 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
Version 1607
Version 1709
Version 1803
Version 1809
Version 1903
Version 1909
Version 2004
All versions
All versions
Microsoft
All versions
Version r2
Microsoft
All versions
Version 1903
Version 1909
Version 2004
All versions
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.1
Version 15.2
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 20.04

References (34)

Source: security@ubuntu.com
Broken LinkMailing ListThird Party Advisory
Source: security@ubuntu.com
Broken LinkMailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Issue TrackingVendor Advisory
Source: security@ubuntu.com
PatchThird Party AdvisoryVendor Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.