Ubuntu Grub2 In Ubuntu vulnerabilities
2 known vulnerabilities affecting ubuntu/grub2_in_ubuntu.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-15707P4MEDIUMCVSS 6.4≥ 20.04 LTS, < 2.04-1ubuntu26.1≥ 18.04 LTS, < 2.02-2ubuntu8.16+2 more2020-07-29
CVE-2020-15707 [MEDIUM] CWE-362 CVE-2020-15707: Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efili
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command
nvd
CVE-2020-15706P4MEDIUMCVSS 6.4≥ 20.04 LTS, < 2.04-1ubuntu26.1≥ 18.04 LTS, < 2.02-2ubuntu8.16+2 more2020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd