ISOMAN

CVE

CVE-2020-15705

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

Severity
MEDIUM
CVSS
6.4
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html
  2. http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html
  3. http://ubuntu.com/security/notices/USN-4432-1
  4. http://www.openwall.com/lists/oss-security/2020/07/29/3
  5. http://www.openwall.com/lists/oss-security/2021/03/02/3
  6. http://www.openwall.com/lists/oss-security/2021/09/17/2
  7. http://www.openwall.com/lists/oss-security/2021/09/17/4
  8. http://www.openwall.com/lists/oss-security/2021/09/21/1
  9. https://access.redhat.com/security/vulnerabilities/grub2bootloader
  10. https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
  11. https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
  12. https://security.gentoo.org/glsa/202104-05
  13. https://security.netapp.com/advisory/ntap-20200731-0008/
  14. https://usn.ubuntu.com/4432-1/
  15. https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass
  16. https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot
  17. https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
  18. https://www.openwall.com/lists/oss-security/2020/07/29/3
  19. https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/
  20. https://www.suse.com/support/kb/doc/?id=000019673