Red Hat Security Advisory: grub2 security and bug fix update
🔗 CVE IDs covered (8)
📋 Description
CVE-2020-10713 — grub2: Crafted grub.cfg file can lead to arbitrary code execution during boot process CVE-2020-14308 — grub2: grub_malloc does not validate allocation size allowing for arithmetic overflow and subsequent heap-based buffer overflow CVE-2020-14309 — grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow CVE-2020-14310 — grub2: Integer overflow read_section_as_string may lead to heap-based buffer overflow CVE-2020-14311 — grub2: Integer overflow in grub_ext2_read_link leads to heap-based buffer overflow CVE-2020-15705 — grub2: Fail kernel validation without shim protocol CVE-2020-15706 — grub2: Use-after-free redefining a function whilst the same function is already executing CVE-2020-15707 — grub2: Integer overflow in initrd size handling
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2020:3275
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/vulnerabilities/grub2bootloader
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1825243
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852014
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852022
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1852030
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1860978
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1861118
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1861581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1861858
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3275.json