CVE-2015-5281
published 2015-11-24CVE-2015-5281: The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot…
PriorityP411low2.6CVSS 2.0
AVLACHAuNCPIPAN
EPSS
0.34%
25.6th percentile
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-626f-gjf6-rgjr: The grub2 package before 2
ghsa_unreviewed·2022-05-17
CVE-2015-5281 [LOW] GHSA-626f-gjf6-rgjr: The grub2 package before 2
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.
Red Hat
grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot
vendor_redhat·2015-11-17·CVSS 2.6
CVE-2015-5281 [LOW] grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot
grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.
It was discovered that grub2 builds for EFI systems contained modules that were not suitable to be loaded in a Secure Boot environment. An attacker could use this flaw to circumvent the Secure Boot mechanisms and load non-verified code. Attacks could use the boot menu if no password was set, or
Debian
CVE-2015-5281: grub2 - The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when us...
vendor_debian·2015·CVSS 2.6
CVE-2015-5281 [LOW] CVE-2015-5281: grub2 - The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when us...
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5281 grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot
bugzilla·2015-09-17·CVSS 2.6
CVE-2015-5281 [LOW] CVE-2015-5281 grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot
CVE-2015-5281 grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot
Quoting from bug #1262904:
"""
Description of problem:
Long long ago somebody committed http://pkgs.devel.redhat.com/cgit/rpms/grub2/commit/?h=rhel-7.2&id=909ac684df7a662e7afd9d45d546ad97d363d197 to our grub2 packages in RHEL 7. While the first hunk is correct, the second hunk is pretty much purely wrong. The last two changes got reverted immediately, but the multiboot and multiboot2 modules remained built in.
Those modules /should not/ function on UEFI systems, but there's no code in them that actually stops them from doing so, and therefore they allow a user to load non-verified code, such as tools to circumvent Secure Boot.
Since Secure Boot is a security feature of RHEL
Eset
Forgotten UEFI shims undermining Secure Boot
blogs_eset·2026-07-14·CVSS 7.8
CVE-2026-8863 [HIGH] Forgotten UEFI shims undermining Secure Boot
ESET researchers identified 11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS). Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits (such as Bootkitty, HybridPetya, or BlackLotus) even on systems with UEFI Secure Boot enabled. We reported our findings to CERT/CC in February 2026, and the vulnerable UEFI applications were revoked on Microsoft’s June 9th, 2026 Patch Tuesday.
While two CVE IDs were assigned to this case to cover the reported shims, CVE-2026-8863 an
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172611.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172942.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2401.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77983http://www.securitytracker.com/id/1034198https://bugzilla.redhat.com/show_bug.cgi?id=1264103http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172611.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172942.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2401.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77983http://www.securitytracker.com/id/1034198https://bugzilla.redhat.com/show_bug.cgi?id=1264103
2015-11-24
Published