CVE-2020-15706
Last modified
CVE-2020-15706 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Grub2 | <= 2.04 |
| Redhat | Enterprise Linux Atomic Host | All versions |
| Redhat | Openshift Container Platform | 4.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 20.04 |
| Debian | Debian Linux | 10.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Suse | Suse Linux Enterprise Server | 11 |
| Suse | Suse Linux Enterprise Server | 12 |
| Suse | Suse Linux Enterprise Server | 15 |
| Microsoft | Windows 10 | All versions |
| Microsoft | Windows 10 | 1607 |
| Microsoft | Windows 10 | 1709 |
| Microsoft | Windows 10 | 1803 |
| Microsoft | Windows 10 | 1809 |
| Microsoft | Windows 10 | 1903 |
| Microsoft | Windows 10 | 1909 |
| Microsoft | Windows 10 | 2004 |
| Microsoft | Windows 8.1 | All versions |
| Microsoft | Windows Rt 8.1 | All versions |
| Microsoft | Windows Server 2012 | All versions |
| Microsoft | Windows Server 2012 | r2 |
| Microsoft | Windows Server 2016 | All versions |
| Microsoft | Windows Server 2016 | 1903 |
| Microsoft | Windows Server 2016 | 1909 |
| Microsoft | Windows Server 2016 | 2004 |
| Microsoft | Windows Server 2019 | All versions |
| Opensuse | Leap | 15.1 |
| Opensuse | Leap | 15.2 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.htmlBroken Link, Mailing List, Third Party Advisory
- http://ubuntu.com/security/notices/USN-4432-1Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/07/29/3Mailing List, Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/grub2bootloaderThird Party Advisory
- https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.htmlIssue Tracking, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011Patch, Third Party Advisory, Vendor Advisory
- https://security.gentoo.org/glsa/202104-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200731-0008/Third Party Advisory
- https://usn.ubuntu.com/4432-1/Third Party Advisory
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypassThird Party Advisory
- https://www.debian.org/security/2020-GRUB-UEFI-SecureBootThird Party Advisory
- https://www.debian.org/security/2020/dsa-4735Third Party Advisory
- https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/07/29/3Mailing List, Third Party Advisory
- https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=000019673Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.htmlBroken Link, Mailing List, Third Party Advisory
- http://ubuntu.com/security/notices/USN-4432-1Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/07/29/3Mailing List, Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/grub2bootloaderThird Party Advisory
- https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.htmlIssue Tracking, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011Patch, Third Party Advisory, Vendor Advisory
- https://security.gentoo.org/glsa/202104-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200731-0008/Third Party Advisory
- https://usn.ubuntu.com/4432-1/Third Party Advisory
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypassThird Party Advisory
- https://www.debian.org/security/2020-GRUB-UEFI-SecureBootThird Party Advisory
- https://www.debian.org/security/2020/dsa-4735Third Party Advisory
- https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/07/29/3Mailing List, Third Party Advisory
- https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=000019673Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15706?
How severe is CVE-2020-15706?
How do I fix CVE-2020-15706?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15700An issue was discovered in Joomla! through 3.9.19. A missing…6.3
- CVE-2020-15701An unhandled exception in check_ignored() in apport/report.p…5.5
- CVE-2020-15702TOCTOU Race Condition vulnerability in apport allows a local…7
- CVE-2020-15703There is no input validation on the Locale property in an ap…3.3
- CVE-2020-15704The modprobe child process in the ./debian/patches/load_ppp_…5.5
- CVE-2020-15705GRUB2 fails to validate kernel signature when booted directl…6.4
- CVE-2020-15707Integer overflows were discovered in the functions grub_cmd_…6.4
- CVE-2020-15708Ubuntu's packaging of libvirt in 20.04 LTS created a control…7.8
- CVE-2020-15709Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.1…5.5
- CVE-2020-1571An elevation of privilege vulnerability exists in Windows Se…7.3
- CVE-2020-15710Potential double free in Bluez 5 module of PulseAudio could …6.1
- CVE-2020-15711In MISP before 2.4.129, setting a favourite homepage was not…8.8
Are you affected by CVE-2020-15706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
