CVE-2020-15706
Description
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
Risk Information
Base Score
6.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.06
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.4 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.5 | Windows |
| GRand Unified Bootloader (USN-4432-1) grub-efi-ia32-bin_2.02-2ubuntu8.16_i386.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-ia32-bin_2.02-2ubuntu8.16_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-ia32-bin_2.04-1ubuntu26.1_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-ia32-bin_2.02~beta2-36ubuntu3.26_i386.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-ia32-bin_2.02~beta2-36ubuntu3.26_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-bin_2.02-2ubuntu8.16_i386.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-bin_2.02-2ubuntu8.16_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-bin_2.04-1ubuntu26.1_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-bin_2.02~beta2-36ubuntu3.26_i386.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-bin_2.02~beta2-36ubuntu3.26_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-signed_1.142.3+2.04-1ubuntu26.1_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-signed_1.93.18+2.02-2ubuntu8.16_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4432-1) grub-efi-amd64-signed_1.66.26+2.02~beta2-36ubuntu3.26_amd64.deb | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update fwupdate-12-6.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update fwupdate-devel-12-6.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update fwupdate-efi-12-6.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update fwupdate-libs-12-6.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-common-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-aa64-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-ia32-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-ia32-cdboot-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-ia32-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-x64-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-x64-cdboot-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-efi-x64-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-pc-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-pc-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-ppc-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-ppc64-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-ppc64le-modules-2.02-0.86.el7_8.noarch.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-tools-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-tools-extra-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update grub2-tools-minimal-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update mokutil-15-7.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update shim-ia32-15-7.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update shim-unsigned-ia32-15-7.el7_9.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update shim-unsigned-x64-15-7.el7_9.x86_64.rpm | Linux |
| (RHSA-2020:3217) grub2 security and bug fix update shim-x64-15-7.el7_8.x86_64.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-2.02-12.31.1.x86_64.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-debuginfo-2.02-12.31.1.x86_64.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-debugsource-2.02-12.31.1.x86_64.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-i386-pc-2.02-12.31.1.x86_64.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-snapper-plugin-2.02-12.31.1.noarch.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-systemd-sleep-plugin-2.02-12.31.1.noarch.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-x86_64-efi-2.02-12.31.1.x86_64.rpm | Linux |
| SUSE-SU-2020:2078-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-x86_64-xen-2.02-12.31.1.noarch.rpm | Linux |
| grub2 security update(DSA-4735-1) grub2_2.02+dfsg1-20+deb10u2_i386.deb | Linux |
| grub2 security update(DSA-4735-1) grub2_2.02+dfsg1-20+deb10u2_amd64.deb | Linux |
| Grub2-efi-ia32 update (ELSA-2020-5786) grub2-efi-ia32-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2020-5786) grub2-efi-ia32-cdboot-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2020-5786) grub2-efi-x64-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2020-5786) grub2-efi-x64-cdboot-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-pc update (ELSA-2020-5786) grub2-pc-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-tools update (ELSA-2020-5786) grub2-tools-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2020-5786) grub2-tools-efi-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2020-5786) grub2-tools-extra-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2020-5786) grub2-tools-minimal-2.02-82.0.2.el8_2.1.x86_64.rpm | Linux |
| Grub2-common update (ELSA-2020-5786) grub2-common-2.02-82.0.2.el8_2.1.noarch.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2020-5786) grub2-efi-aa64-modules-2.02-82.0.2.el8_2.1.noarch.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2020-5786) grub2-efi-ia32-modules-2.02-82.0.2.el8_2.1.noarch.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2020-5786) grub2-efi-x64-modules-2.02-82.0.2.el8_2.1.noarch.rpm | Linux |
| Grub2-pc-modules update (ELSA-2020-5786) grub2-pc-modules-2.02-82.0.2.el8_2.1.noarch.rpm | Linux |
| Grub2-common update (ELSA-2022-5095) grub2-common-2.02-123.0.4.el8_6.8.noarch.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2022-5095) grub2-efi-aa64-modules-2.02-123.0.4.el8_6.8.noarch.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2022-5095) grub2-efi-ia32-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2022-5095) grub2-efi-ia32-cdboot-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2022-5095) grub2-efi-ia32-modules-2.02-123.0.4.el8_6.8.noarch.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2022-5095) grub2-efi-x64-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2022-5095) grub2-efi-x64-cdboot-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2022-5095) grub2-efi-x64-modules-2.02-123.0.4.el8_6.8.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2022-5095) grub2-pc-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2022-5095) grub2-pc-modules-2.02-123.0.4.el8_6.8.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2022-5095) grub2-tools-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2022-5095) grub2-tools-efi-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2022-5095) grub2-tools-extra-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2022-5095) grub2-tools-minimal-2.02-123.0.4.el8_6.8.x86_64.rpm | Linux |
| Grub2-common update (ELSA-2022-9595) grub2-common-2.02-123.0.7.el8_6.8.noarch.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2022-9595) grub2-efi-aa64-modules-2.02-123.0.7.el8_6.8.noarch.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2022-9595) grub2-efi-ia32-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2022-9595) grub2-efi-ia32-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2022-9595) grub2-efi-ia32-modules-2.02-123.0.7.el8_6.8.noarch.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2022-9595) grub2-efi-x64-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2022-9595) grub2-efi-x64-cdboot-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2022-9595) grub2-efi-x64-modules-2.02-123.0.7.el8_6.8.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2022-9595) grub2-pc-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2022-9595) grub2-pc-modules-2.02-123.0.7.el8_6.8.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2022-9595) grub2-tools-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2022-9595) grub2-tools-efi-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2022-9595) grub2-tools-extra-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2022-9595) grub2-tools-minimal-2.02-123.0.7.el8_6.8.x86_64.rpm | Linux |
| Grub2-common update (ELSA-2023-0049) grub2-common-2.02-142.0.3.el8_7.1.noarch.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2023-0049) grub2-efi-aa64-modules-2.02-142.0.3.el8_7.1.noarch.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2023-0049) grub2-efi-ia32-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2023-0049) grub2-efi-ia32-cdboot-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2023-0049) grub2-efi-ia32-modules-2.02-142.0.3.el8_7.1.noarch.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2023-0049) grub2-efi-x64-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2023-0049) grub2-efi-x64-cdboot-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2023-0049) grub2-efi-x64-modules-2.02-142.0.3.el8_7.1.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2023-0049) grub2-pc-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2023-0049) grub2-pc-modules-2.02-142.0.3.el8_7.1.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2023-0049) grub2-tools-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2023-0049) grub2-tools-efi-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2023-0049) grub2-tools-extra-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2023-0049) grub2-tools-minimal-2.02-142.0.3.el8_7.1.x86_64.rpm | Linux |
| (RHSA-2020:3217)Moderate: security and bug fix update fwupdate-debuginfo-12-6.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217)Moderate: security and bug fix update grub2-debuginfo-2.02-0.86.el7_8.x86_64.rpm | Linux |
| (RHSA-2020:3217)Moderate: security and bug fix update mokutil-debuginfo-15-7.el7_8.x86_64.rpm | Linux |
| Grub2-common update (ELSA-2024-3184) grub2-common-2.02-156.0.1.el8.noarch.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2024-3184) grub2-efi-aa64-modules-2.02-156.0.1.el8.noarch.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2024-3184) grub2-efi-ia32-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2024-3184) grub2-efi-ia32-cdboot-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2024-3184) grub2-efi-ia32-modules-2.02-156.0.1.el8.noarch.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2024-3184) grub2-efi-x64-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2024-3184) grub2-efi-x64-cdboot-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2024-3184) grub2-efi-x64-modules-2.02-156.0.1.el8.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2024-3184) grub2-pc-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2024-3184) grub2-pc-modules-2.02-156.0.1.el8.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2024-3184) grub2-tools-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2024-3184) grub2-tools-efi-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2024-3184) grub2-tools-extra-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2024-3184) grub2-tools-minimal-2.02-156.0.1.el8.x86_64.rpm | Linux |
| Grub2-common update (ELSA-2025-3367) grub2-common-2.02-162.0.2.el8_10.noarch.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2025-3367) grub2-efi-ia32-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2025-3367) grub2-efi-ia32-cdboot-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2025-3367) grub2-efi-ia32-modules-2.02-162.0.2.el8_10.noarch.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2025-3367) grub2-efi-x64-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2025-3367) grub2-efi-x64-cdboot-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2025-3367) grub2-efi-x64-modules-2.02-162.0.2.el8_10.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2025-3367) grub2-pc-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2025-3367) grub2-pc-modules-2.02-162.0.2.el8_10.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2025-3367) grub2-tools-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2025-3367) grub2-tools-efi-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2025-3367) grub2-tools-extra-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2025-3367) grub2-tools-minimal-2.02-162.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2025-3367) grub2-efi-aa64-modules-2.02-162.0.2.el8_10.noarch.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2025-3367) grub2-efi-x64-cdboot-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2025-3367) grub2-efi-x64-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2025-3367) grub2-efi-ia32-modules-2.02-164.0.2.el8_10.noarch.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2025-3367) grub2-efi-ia32-cdboot-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2025-3367) grub2-efi-ia32-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-efi-aa64-modules update (ELSA-2025-3367) grub2-efi-aa64-modules-2.02-164.0.2.el8_10.noarch.rpm | Linux |
| Grub2-common update (ELSA-2025-3367) grub2-common-2.02-164.0.2.el8_10.noarch.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2025-3367) grub2-efi-x64-modules-2.02-164.0.2.el8_10.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2025-3367) grub2-pc-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2025-3367) grub2-pc-modules-2.02-164.0.2.el8_10.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2025-3367) grub2-tools-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-tools-efi update (ELSA-2025-3367) grub2-tools-efi-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2025-3367) grub2-tools-extra-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2025-3367) grub2-tools-minimal-2.02-164.0.2.el8_10.x86_64.rpm | Linux |
| Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2020-15706) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234