CVE-2020-14309
published 2020-07-30CVE-2020-14309: There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.48%
38.8th percentile
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.04-9 (bookworm) | grub2 2.04-9 (bookworm) |
| gnu | grub2 | < 2.06 | 2.06 |
| gnu | grub2 | >= 0 < 2.04-9 | 2.04-9 |
| gnu | grub2 | >= 0 < 2.04-9 | 2.04-9 |
| gnu | grub2 | >= 0 < 2.04-9 | 2.04-9 |
| gnu | grub2 | >= 0 < 2.04-9 | 2.04-9 |
| gnu | grub2 | >= 0 < 2.02~beta2-36ubuntu3.26 | 2.02~beta2-36ubuntu3.26 |
| gnu | grub2 | >= 0 < 2.02~beta2-36ubuntu3.27 | 2.02~beta2-36ubuntu3.27 |
| gnu | grub2 | >= 0 < 2.02-2ubuntu8.16 | 2.02-2ubuntu8.16 |
| gnu | grub2 | >= 0 < 2.02-2ubuntu8.17 | 2.02-2ubuntu8.17 |
| gnu | grub2 | >= 0 < 2.04-1ubuntu26.1 | 2.04-1ubuntu26.1 |
| gnu | grub2 | >= 0 < 2.04-1ubuntu26.2 | 2.04-1ubuntu26.2 |
| gnu | grub2 | >= 0 < 2.02~beta2-9ubuntu1.20 | 2.02~beta2-9ubuntu1.20 |
| gnu | grub2 | >= 0 < 2.02~beta2-9ubuntu1.21 | 2.02~beta2-9ubuntu1.21 |
| msrc | cbl2_grub2_2.06rc1-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_grub2_2.06rc1-4_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8whj-mpcj-4jv6: There's an issue with grub2 in all versions before 2
ghsa_unreviewed·2022-05-24
CVE-2020-14309 [MEDIUM] CWE-190 GHSA-8whj-mpcj-4jv6: There's an issue with grub2 in all versions before 2
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
OSV
grub2, grub2-signed regression
osv·2020-08-04·CVSS 8.2
[HIGH] grub2, grub2-signed regression
grub2, grub2-signed regression
USN-4432-1 fixed vulnerabilities in GRUB2 affecting Secure Boot
environments. Unfortunately, the update introduced regressions for
some BIOS systems (either pre-UEFI or UEFI configured in Legacy mode),
preventing them from successfully booting. This update addresses
the issue.
Users with BIOS systems that installed GRUB2 versions from USN-4432-1
should verify that their GRUB2 installation has a correct understanding
of their boot device location and installed the boot loader correctly.
We apologize for the inconvenience.
Original advisory details:
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to
OSV
CVE-2020-14309: There's an issue with grub2 in all versions before 2
osv·2020-07-30·CVSS 6.7
CVE-2020-14309 [MEDIUM] CVE-2020-14309: There's an issue with grub2 in all versions before 2
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
OSV
grub2, grub2-signed vulnerabilities
osv·2020-07-29·CVSS 8.2
CVE-2020-10713 [HIGH] grub2, grub2-signed vulnerabilities
grub2, grub2-signed vulnerabilities
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-10713)
Chris Coulson discovered that the GRUB2 function handling code did not
properly handle a function being redefined, leading to a use-after-free
vulnerability. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-15706)
Chris Coulson discovered that multiple integer overflows existed in GRUB2
when handling certain filesystems or font files, leading to heap-based
buffer overflows. A local attacker could use the
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Palo Alto
PAN
vendor_paloalto·2020-08-12·CVSS 8.2
CVE-2020-10713 [HIGH] CWE-120 PAN
PAN
Palo Alto Networks is aware of the vulnerability known as BootHole (CVE-2020-10713) that affects the Grand Unified Bootloader (GRUB) used in Palo Alto Networks PAN-OS software. BootHole is a buffer overflow vulnerability that occurs in GRUB2 when parsing an attacker-controlled grub.cfg file. This vulnerability enables arbitrary code execution within the boot environment, which allows persistent control of the system. It is not possible for malicious actors or PAN-OS administrators to exploit this vulnerability under normal conditions. Administrators do not have access to the grub configuration file nor do they have permission to modify it. An attacker would need to first compromise the system and then get the root Linux privileges necessary to perform these actions before they could e
Ubuntu
GRUB2 regression
vendor_ubuntu·2020-08-04·CVSS 8.2
[HIGH] GRUB2 regression
Title: GRUB2 regression
Summary: USN-4432-1 introduced a regression in the GRUB2 bootloader.
USN-4432-1 fixed vulnerabilities in GRUB2 affecting Secure Boot
environments. Unfortunately, the update introduced regressions for
some BIOS systems (either pre-UEFI or UEFI configured in Legacy mode),
preventing them from successfully booting. This update addresses
the issue.
Users with BIOS systems that installed GRUB2 versions from USN-4432-1
should verify that their GRUB2 installation has a correct understanding
of their boot device location and installed the boot loader correctly.
We apologize for the inconvenience.
Original advisory details:
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
Ubuntu
GRUB 2 vulnerabilities
vendor_ubuntu·2020-07-29·CVSS 8.2
CVE-2020-14309 [HIGH] GRUB 2 vulnerabilities
Title: GRUB 2 vulnerabilities
Summary: Several security issues were fixed in GRUB 2.
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-10713)
Chris Coulson discovered that the GRUB2 function handling code did not
properly handle a function being redefined, leading to a use-after-free
vulnerability. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-15706)
Chris Coulson discovered that multiple integer overflows existed in GRUB2
when handling certain filesystems or font files, leading to heap-base
Red Hat
grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
vendor_redhat·2020-07-29·CVSS 6.7
CVE-2020-14309 [MEDIUM] CWE-190 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
A flaw was found in grub2. When handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size, the name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system av
Microsoft
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic ove
vendor_msrc·2020-07-14·CVSS 6.7
CVE-2020-14309 [MEDIUM] CWE-787 There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic ove
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in Octobe
Debian
CVE-2020-14309: grub2 - There's an issue with grub2 in all versions before 2.06 when handling squashfs f...
vendor_debian·2020·CVSS 6.7
CVE-2020-14309 [MEDIUM] CVE-2020-14309: grub2 - There's an issue with grub2 in all versions before 2.06 when handling squashfs f...
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
Scope: local
bookworm: resolved (fixed in 2.04-9)
bullseye: resolved (fixed in 2.04-9)
forky: resolved (fixed in 2.04-9)
sid: resolved (fixed in 2.04-9)
trixie: resolved (fixed in 2.04-9)
No detection rules found.
No public exploits indexed.
Qualys
GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) - Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
blogs_qualys·2020-08-03·CVSS 8.2
CVE-2020-10713 [HIGH] GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) - Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
On July 29, 2020, Eclypsium researchers disclosed a high-risk vulnerability in GRUB2 (GRand Unified Bootloader version 2) affecting billions of Linux and Windows systems, even when secure boot is enabled. CVE-2020-10713 is assigned to this buffer overflow vulnerability, termed as “Boothole”.
Successful exploitation of the vulnerability requires high privileges or physical access to the device. According to Eclypsium researchers, “attackers exploiting this vulnerability can install persistent and stealthy bootkits or malicious bootloaders that could give them near-total control over the victim device.”
Secure Boot is designed to verify all the firmware of the computer is trusted. However, CVE-2020-10713 results in total pwn of secure boot in systems using GRUB. The bug resides in GRUB’s i
Qualys
GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
blogs_qualys·2020-08-03·CVSS 8.2
CVE-2020-10713 [HIGH] GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
On July 29, 2020, Eclypsium researchers disclosed a high-risk vulnerability in GRUB2 (GRand Unified Bootloader version 2) affecting billions of Linux and Windows systems, even when secure boot is enabled. CVE-2020-10713 is assigned to this buffer overflow vulnerability, termed as “Boothole”.
Successful exploitation of the vulnerability requires high privileges or physical access to the device. According to Eclypsium researchers , “attackers exploiting this vulnerability can install persistent and stealthy bootkits or malicious bootloaders that could give them near-total control over the victim device.”
Secure Boot is designed to verify all the firmware of the computer is trusted. However, CVE-2020-10713 results in total pwn of secure boot in systems using GRUB. The bug resides in GRUB’s
Tenable
CVE-2020-10713: “BootHole” GRUB2 Bootloader Arbitrary Code Execution Vulnerability
blogs_tenable·2020-07-29·CVSS 8.2
[HIGH] CVE-2020-10713: “BootHole” GRUB2 Bootloader Arbitrary Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow [fedora-all]
bugzilla·2020-08-03·CVSS 6.7
CVE-2020-14309 [MEDIUM] CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow [fedora-all]
CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
bugzilla·2020-06-29·CVSS 6.7
CVE-2020-14309 [MEDIUM] CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
CVE-2020-14309 grub2: Integer overflow in grub_squash_read_symlink may lead to heap-based buffer overflow
Integer overflow in grub_squash_read_symlink triggered by a specially crafted squashfs filesystem containing a symlink inode with a name length of UINT32, which leads to a zero-sized allocation and subsequent heap buffer overflow with attacker controlled data.
Discussion:
Acknowledgments:
Name: Chris Coulson (Ubuntu Security Team)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:3216 https://access.redhat.com/errata/RHSA-2020:3216
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-14309
---
This issue has been addressed
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1852022https://security.gentoo.org/glsa/202104-05https://security.netapp.com/advisory/ntap-20200731-0008/https://usn.ubuntu.com/4432-1/http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1852022https://security.gentoo.org/glsa/202104-05https://security.netapp.com/advisory/ntap-20200731-0008/https://usn.ubuntu.com/4432-1/
2020-07-30
Published