CVE-2020-15707
6.4
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD
Description
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.
Affected (33)
Products: Gnu: Grub2 · Redhat: Enterprise Linux, Enterprise Linux Atomic Host, Openshift Container Platform · Microsoft: Windows 10, Windows 8.1, Windows Rt 8.1, Windows Server 2012, Windows Server 2016, Windows Server 2019 · +5 more
Show all products
Gnu: Grub2 · Redhat: Enterprise Linux, Enterprise Linux Atomic Host, Openshift Container Platform · Microsoft: Windows 10, Windows 8.1, Windows Rt 8.1, Windows Server 2012, Windows Server 2016, Windows Server 2019 · Canonical: Ubuntu Linux · Debian: Debian Linux · Opensuse: Leap · Suse: Suse Linux Enterprise Server · Netapp: Active Iq Unified Manager
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 | |
| All versions | |
| Version 4.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 15.1 | |
| Version 11 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.5 |
Related CWEs
CWE-190
Integer Overflow or Wraparound
The product performs a calculation that can
produce an integer overflow or wraparound when the logic
assumes that the resulting value will always be larger than
the original value. This occurs when an integer value is
incremented to a value that is too large to store in the
associated representation. When this occurs, the value may
become a very small or negative number.
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
References (34)
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Issue TrackingVendor Advisory
Source: security@ubuntu.com
PatchThird Party AdvisoryVendor Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
ExploitThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.