Debian Grub2 vulnerabilities
69 known vulnerabilities affecting debian/grub2.
Total CVEs
69
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM36LOW13
Vulnerabilities
Page 3 of 4
CVE-2022-28735MEDIUMCVSS 6.7fixed in grub2 2.06-3 (bookworm)2022
CVE-2022-28735 [MEDIUM] CVE-2022-28735: grub2 - The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powe...
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
Scope: local
bookworm: resolved (fixed in 2.06-3)
bullseye: resolved (fixed in 2.06-3~deb11u1)
forky: resolved (fixed in 2.06-3)
s
debian
CVE-2022-28736MEDIUMCVSS 6.4fixed in grub2 2.06-3 (bookworm)2022
CVE-2022-28736 [MEDIUM] CVE-2022-28736: grub2 - There's a use-after-free vulnerability in grub_cmd_chainloader() function; The c...
There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free vulnerability is triggered. If an attacker can control the GRUB2's memory allocation pattern sensit
debian
CVE-2021-3697HIGHCVSS 7.0fixed in grub2 2.06-3 (bookworm)2021
CVE-2021-3697 [HIGH] CVE-2021-3697: grub2 - A crafted JPEG image may lead the JPEG reader to underflow its data pointer, all...
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot c
debian
CVE-2021-20233HIGHCVSS 8.2fixed in grub2 2.04-16 (bookworm)2021
CVE-2021-20233 [HIGH] CVE-2021-20233: grub2 - A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the me...
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulner
debian
CVE-2021-3696MEDIUMCVSS 4.5fixed in grub2 2.06-3 (bookworm)2021
CVE-2021-3696 [MEDIUM] CVE-2021-3696: grub2 - A heap out-of-bounds write may heppen during the handling of Huffman tables in t...
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code executi
debian
CVE-2021-3695MEDIUMCVSS 4.5fixed in grub2 2.06-3 (bookworm)2021
CVE-2021-3695 [MEDIUM] CVE-2021-3695: grub2 - A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the he...
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifca
debian
CVE-2021-20225MEDIUMCVSS 6.7fixed in grub2 2.04-16 (bookworm)2021
CVE-2021-20225 [MEDIUM] CVE-2021-20225: grub2 - A flaw was found in grub2 in versions prior to 2.06. The option parser allows an...
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolv
debian
CVE-2021-3418LOWCVSS 6.42021
CVE-2021-3418 [MEDIUM] CVE-2021-3418: grub2 - If certificates that signed grub are installed into db, grub can be booted direc...
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upst
debian
CVE-2021-3981LOWCVSS 3.3fixed in grub2 2.06-8 (bookworm)2021
CVE-2021-3981 [LOW] CVE-2021-3981: grub2 - A flaw in grub2 was found where its configuration file, known as grub.cfg, is be...
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has
debian
CVE-2021-46705LOWCVSS 5.12021
CVE-2021-46705 [MEDIUM] CVE-2021-46705: grub2 - A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Ente...
A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.
Scope: local
bookworm: resolved
bullseye: r
debian
CVE-2020-27779HIGHCVSS 7.5fixed in grub2 2.04-16 (bookworm)2020
CVE-2020-27779 [HIGH] CVE-2020-27779: grub2 - A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not...
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity a
debian
CVE-2020-25632HIGHCVSS 8.2fixed in grub2 2.04-16 (bookworm)2020
CVE-2020-25632 [HIGH] CVE-2020-25632: grub2 - A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation al...
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to d
debian
CVE-2020-25647HIGHCVSS 7.6fixed in grub2 2.04-16 (bookworm)2020
CVE-2020-25647 [HIGH] CVE-2020-25647: grub2 - A flaw was found in grub2 in versions prior to 2.06. During USB device initializ...
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from t
debian
CVE-2020-10713HIGHCVSS 8.2fixed in grub2 2.04-9 (bookworm)2020
CVE-2020-10713 [HIGH] CVE-2020-10713: grub2 - A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2...
A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alt
debian
CVE-2020-14372HIGHCVSS 7.5fixed in grub2 2.04-16 (bookworm)2020
CVE-2020-14372 [HIGH] CVE-2020-14372: grub2 - A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enable...
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded an
debian
CVE-2020-27749MEDIUMCVSS 6.7fixed in grub2 2.04-16 (bookworm)2020
CVE-2020-27749 [MEDIUM] CVE-2020-27749: grub2 - A flaw was found in grub2 in versions prior to 2.06. Variable names present are ...
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If the function is called with a command line that references a variable with a sufficiently large payload, it is possible
debian
CVE-2020-15707MEDIUMCVSS 5.7fixed in grub2 2.04-9 (bookworm)2020
CVE-2020-15707 [MEDIUM] CVE-2020-15707: grub2 - Integer overflows were discovered in the functions grub_cmd_initrd and grub_init...
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit archite
debian
CVE-2020-14308MEDIUMCVSS 6.4fixed in grub2 2.04-9 (bookworm)2020
CVE-2020-14308 [MEDIUM] CVE-2020-14308: grub2 - In grub2 versions before 2.06 the grub memory allocator doesn't check for possib...
In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process.
Scope: local
bookworm: resolved (fixed in 2.04-9
debian
CVE-2020-14310MEDIUMCVSS 5.7fixed in grub2 2.04-9 (bookworm)2020
CVE-2020-14310 [MEDIUM] CVE-2020-14310: grub2 - There is an issue on grub2 before version 2.06 at function read_section_as_strin...
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_
debian
CVE-2020-14309MEDIUMCVSS 6.7fixed in grub2 2.04-9 (bookworm)2020
CVE-2020-14309 [MEDIUM] CVE-2020-14309: grub2 - There's an issue with grub2 in all versions before 2.06 when handling squashfs f...
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
Scope: local
bookworm: resolved (fixed in 2.04-9)
bu
debian