CVE-2020-15705
published 2020-07-29CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel…
PriorityP430medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
1.39%
69.3th percentile
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | grub2 | — | — |
| gnu | grub2 | < 2.06 | 2.06 |
| gnu | grub2 | <= 2.04 | — |
| gnu | grub2 | — | — |
| gnu | grub2 | >= 0 < 2.02~beta2-36ubuntu3.26 | 2.02~beta2-36ubuntu3.26 |
| gnu | grub2 | >= 0 < 2.02~beta2-36ubuntu3.27 | 2.02~beta2-36ubuntu3.27 |
| gnu | grub2 | >= 0 < 2.02-2ubuntu8.16 | 2.02-2ubuntu8.16 |
| gnu | grub2 | >= 0 < 2.02-2ubuntu8.17 | 2.02-2ubuntu8.17 |
| gnu | grub2 | >= 0 < 2.04-1ubuntu26.1 | 2.04-1ubuntu26.1 |
| gnu | grub2 | >= 0 < 2.04-1ubuntu26.2 | 2.04-1ubuntu26.2 |
| gnu | grub2 | >= 0 < 2.02~beta2-9ubuntu1.20 | 2.02~beta2-9ubuntu1.20 |
| gnu | grub2 | >= 0 < 2.02~beta2-9ubuntu1.21 | 2.02~beta2-9ubuntu1.21 |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian6.4LOW
vendor_msrc6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Microsoft
If certificates that signed grub are installed into db grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot
vendor_msrc·2021-03-09·CVSS 6.4
CVE-2021-3418 [MEDIUM] CWE-281 If certificates that signed grub are installed into db grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot
If certificates that signed grub are installed into db grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compose
Red Hat
grub2: grub 2.05 reintroduced CVE-2020-15705
vendor_redhat·2021-03-02·CVSS 6.4
CVE-2021-3418 [MEDIUM] CWE-281 grub2: grub 2.05 reintroduced CVE-2020-15705
grub2: grub 2.05 reintroduced CVE-2020-15705
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.
A flaw was found in grub. If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CV
Debian
CVE-2021-3418: grub2 - If certificates that signed grub are installed into db, grub can be booted direc...
vendor_debian·2021·CVSS 6.4
CVE-2021-3418 [MEDIUM] CVE-2021-3418: grub2 - If certificates that signed grub are installed into db, grub can be booted direc...
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Palo Alto
PAN
vendor_paloalto·2020-08-12·CVSS 8.2
CVE-2020-10713 [HIGH] CWE-120 PAN
PAN
Palo Alto Networks is aware of the vulnerability known as BootHole (CVE-2020-10713) that affects the Grand Unified Bootloader (GRUB) used in Palo Alto Networks PAN-OS software. BootHole is a buffer overflow vulnerability that occurs in GRUB2 when parsing an attacker-controlled grub.cfg file. This vulnerability enables arbitrary code execution within the boot environment, which allows persistent control of the system. It is not possible for malicious actors or PAN-OS administrators to exploit this vulnerability under normal conditions. Administrators do not have access to the grub configuration file nor do they have permission to modify it. An attacker would need to first compromise the system and then get the root Linux privileges necessary to perform these actions before they could e
Ubuntu
GRUB2 regression
vendor_ubuntu·2020-08-04·CVSS 8.2
[HIGH] GRUB2 regression
Title: GRUB2 regression
Summary: USN-4432-1 introduced a regression in the GRUB2 bootloader.
USN-4432-1 fixed vulnerabilities in GRUB2 affecting Secure Boot
environments. Unfortunately, the update introduced regressions for
some BIOS systems (either pre-UEFI or UEFI configured in Legacy mode),
preventing them from successfully booting. This update addresses
the issue.
Users with BIOS systems that installed GRUB2 versions from USN-4432-1
should verify that their GRUB2 installation has a correct understanding
of their boot device location and installed the boot loader correctly.
We apologize for the inconvenience.
Original advisory details:
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
Ubuntu
GRUB 2 vulnerabilities
vendor_ubuntu·2020-07-29·CVSS 8.2
CVE-2020-14309 [HIGH] GRUB 2 vulnerabilities
Title: GRUB 2 vulnerabilities
Summary: Several security issues were fixed in GRUB 2.
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-10713)
Chris Coulson discovered that the GRUB2 function handling code did not
properly handle a function being redefined, leading to a use-after-free
vulnerability. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-15706)
Chris Coulson discovered that multiple integer overflows existed in GRUB2
when handling certain filesystems or font files, leading to heap-base
Red Hat
grub2: Fail kernel validation without shim protocol
vendor_redhat·2020-07-29·CVSS 6.4
CVE-2020-15705 [MEDIUM] CWE-440 grub2: Fail kernel validation without shim protocol
grub2: Fail kernel validation without shim protocol
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
Microsoft
GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
vendor_msrc·2020-07-14·CVSS 6.4
CVE-2020-15705 [MEDIUM] CWE-347 GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediatio
Debian
CVE-2020-15705: grub2 - GRUB2 fails to validate kernel signature when booted directly without shim, allo...
vendor_debian·2020·CVSS 6.4
CVE-2020-15705 [MEDIUM] CVE-2020-15705: grub2 - GRUB2 fails to validate kernel signature when booted directly without shim, allo...
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-w739-fjv8-98pq: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed
ghsa_unreviewed·2022-05-24
CVE-2020-15705 [MEDIUM] CWE-347 GHSA-w739-fjv8-98pq: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
GHSA
GHSA-j6wm-c7q8-jcx7: If certificates that signed grub are installed into db, grub can be booted directly
ghsa_unreviewed·2022-05-24·CVSS 6.4
CVE-2021-3418 [MEDIUM] CWE-281 GHSA-j6wm-c7q8-jcx7: If certificates that signed grub are installed into db, grub can be booted directly
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grbu2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.
OSV
CVE-2021-3418: If certificates that signed grub are installed into db, grub can be booted directly
osv·2021-03-15·CVSS 6.4
CVE-2021-3418 [MEDIUM] CVE-2021-3418: If certificates that signed grub are installed into db, grub can be booted directly
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.
OSV
grub2, grub2-signed regression
osv·2020-08-04·CVSS 8.2
[HIGH] grub2, grub2-signed regression
grub2, grub2-signed regression
USN-4432-1 fixed vulnerabilities in GRUB2 affecting Secure Boot
environments. Unfortunately, the update introduced regressions for
some BIOS systems (either pre-UEFI or UEFI configured in Legacy mode),
preventing them from successfully booting. This update addresses
the issue.
Users with BIOS systems that installed GRUB2 versions from USN-4432-1
should verify that their GRUB2 installation has a correct understanding
of their boot device location and installed the boot loader correctly.
We apologize for the inconvenience.
Original advisory details:
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to
OSV
CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed
osv·2020-07-29·CVSS 6.4
CVE-2020-15705 [MEDIUM] CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
OSV
grub2, grub2-signed vulnerabilities
osv·2020-07-29·CVSS 8.2
CVE-2020-10713 [HIGH] grub2, grub2-signed vulnerabilities
grub2, grub2-signed vulnerabilities
Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-10713)
Chris Coulson discovered that the GRUB2 function handling code did not
properly handle a function being redefined, leading to a use-after-free
vulnerability. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-15706)
Chris Coulson discovered that multiple integer overflows existed in GRUB2
when handling certain filesystems or font files, leading to heap-based
buffer overflows. A local attacker could use the
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15705 grub2: Fail kernel validation without shim protocol [fedora-all]
bugzilla·2020-08-03·CVSS 6.4
CVE-2020-15705 [MEDIUM] CVE-2020-15705 grub2: Fail kernel validation without shim protocol [fedora-all]
CVE-2020-15705 grub2: Fail kernel validation without shim protocol [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2020-15705 grub2: Fail kernel validation without shim protocol
bugzilla·2020-07-27·CVSS 6.4
CVE-2020-15705 [MEDIUM] CVE-2020-15705 grub2: Fail kernel validation without shim protocol
CVE-2020-15705 grub2: Fail kernel validation without shim protocol
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:3216 https://access.redhat.com/errata/RHSA-2020:3216
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-15705
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3217 https://access.redhat.c
Qualys
GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) - Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
blogs_qualys·2020-08-03·CVSS 8.2
CVE-2020-10713 [HIGH] GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) - Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
On July 29, 2020, Eclypsium researchers disclosed a high-risk vulnerability in GRUB2 (GRand Unified Bootloader version 2) affecting billions of Linux and Windows systems, even when secure boot is enabled. CVE-2020-10713 is assigned to this buffer overflow vulnerability, termed as “Boothole”.
Successful exploitation of the vulnerability requires high privileges or physical access to the device. According to Eclypsium researchers, “attackers exploiting this vulnerability can install persistent and stealthy bootkits or malicious bootloaders that could give them near-total control over the victim device.”
Secure Boot is designed to verify all the firmware of the computer is trusted. However, CVE-2020-10713 results in total pwn of secure boot in systems using GRUB. The bug resides in GRUB’s i
Qualys
GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
blogs_qualys·2020-08-03·CVSS 8.2
CVE-2020-10713 [HIGH] GRUB2 Boothole Buffer Overflow Vulnerability (CVE-2020-10713) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
On July 29, 2020, Eclypsium researchers disclosed a high-risk vulnerability in GRUB2 (GRand Unified Bootloader version 2) affecting billions of Linux and Windows systems, even when secure boot is enabled. CVE-2020-10713 is assigned to this buffer overflow vulnerability, termed as “Boothole”.
Successful exploitation of the vulnerability requires high privileges or physical access to the device. According to Eclypsium researchers , “attackers exploiting this vulnerability can install persistent and stealthy bootkits or malicious bootloaders that could give them near-total control over the victim device.”
Secure Boot is designed to verify all the firmware of the computer is trusted. However, CVE-2020-10713 results in total pwn of secure boot in systems using GRUB. The bug resides in GRUB’s
Tenable
CVE-2020-10713: “BootHole” GRUB2 Bootloader Arbitrary Code Execution Vulnerability
blogs_tenable·2020-07-29·CVSS 8.2
[HIGH] CVE-2020-10713: “BootHole” GRUB2 Bootloader Arbitrary Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.htmlhttp://ubuntu.com/security/notices/USN-4432-1http://www.openwall.com/lists/oss-security/2020/07/29/3http://www.openwall.com/lists/oss-security/2021/03/02/3http://www.openwall.com/lists/oss-security/2021/09/17/2http://www.openwall.com/lists/oss-security/2021/09/17/4http://www.openwall.com/lists/oss-security/2021/09/21/1https://access.redhat.com/security/vulnerabilities/grub2bootloaderhttps://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011https://security.gentoo.org/glsa/202104-05https://security.netapp.com/advisory/ntap-20200731-0008/https://usn.ubuntu.com/4432-1/https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypasshttps://www.debian.org/security/2020-GRUB-UEFI-SecureBoothttps://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/https://www.openwall.com/lists/oss-security/2020/07/29/3https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/https://www.suse.com/support/kb/doc/?id=000019673http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.htmlhttp://ubuntu.com/security/notices/USN-4432-1http://www.openwall.com/lists/oss-security/2020/07/29/3http://www.openwall.com/lists/oss-security/2021/03/02/3http://www.openwall.com/lists/oss-security/2021/09/17/2http://www.openwall.com/lists/oss-security/2021/09/17/4http://www.openwall.com/lists/oss-security/2021/09/21/1https://access.redhat.com/security/vulnerabilities/grub2bootloaderhttps://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011https://security.gentoo.org/glsa/202104-05https://security.netapp.com/advisory/ntap-20200731-0008/https://usn.ubuntu.com/4432-1/https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypasshttps://www.debian.org/security/2020-GRUB-UEFI-SecureBoothttps://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/https://www.openwall.com/lists/oss-security/2020/07/29/3https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/https://www.suse.com/support/kb/doc/?id=000019673
2020-07-29
Published