CVE-2020-15705

Name
CVE-2020-15705
Description
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://www.suse.com/support/kb/doc/?id=000019673
Third Party Advisory http://ubuntu.com/security/notices/USN-4432-1
Issue Tracking https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
Third Party Advisory https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass
Third Party Advisory https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot
Patch https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
Third Party Advisory https://access.redhat.com/security/vulnerabilities/grub2bootloader
Third Party Advisory https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
Third Party Advisory https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/
Mailing List https://www.openwall.com/lists/oss-security/2020/07/29/3
Mailing List http://www.openwall.com/lists/oss-security/2020/07/29/3
Third Party Advisory https://security.netapp.com/advisory/ntap-20200731-0008/
Third Party Advisory https://usn.ubuntu.com/4432-1/
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html
Mailing List http://www.openwall.com/lists/oss-security/2021/03/02/3
GENTOO https://security.gentoo.org/glsa/202104-05
MLIST http://www.openwall.com/lists/oss-security/2021/09/17/2
MLIST http://www.openwall.com/lists/oss-security/2021/09/17/4
MLIST http://www.openwall.com/lists/oss-security/2021/09/21/1

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* grub2 >= None <= 2.04

Vulnerable and fixed packages

Source package Branch Version Maintainer Status