← Back

CVE-2020-15707

nvd nist
Published: Jul 29, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.4
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD

Description

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.

Affected (33)

Show all products
1 product
Grub2
3 products
Enterprise Linux
Enterprise Linux Atomic Host
Openshift Container Platform
6 products
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012
Windows Server 2016
Windows Server 2019
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Leap
1 product
Suse Linux Enterprise Server
1 product
Active Iq Unified Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.04
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 7.0
Version 8.0
All versions
Version 4.0
Configuration C
17 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
Version 1607
Version 1709
Version 1803
Version 1809
Version 1903
Version 1909
Version 2004
All versions
All versions
Microsoft
All versions
Version r2
Microsoft
All versions
Version 1903
Version 1909
Version 2004
All versions
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 20.04
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.1
Version 15.2
Suse
Version 11
Version 12
Version 15
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
From 9.5

References (34)

Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Issue TrackingVendor Advisory
Source: security@ubuntu.com
PatchThird Party AdvisoryVendor Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
ExploitThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.