CVE-2020-25632
Description
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Information
Base Score
8.2
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.016
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| grub2 security update(DSA-4867-1) grub2_2.02+dfsg1-20+deb10u4_i386.deb | Linux |
| grub2 security update(DSA-4867-1) grub2_2.02+dfsg1-20+deb10u4_amd64.deb | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-2.02-12.47.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-debuginfo-2.02-12.47.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-debugsource-2.02-12.47.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-i386-pc-2.02-12.47.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-snapper-plugin-2.02-12.47.1.noarch.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-systemd-sleep-plugin-2.02-12.47.1.noarch.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-x86_64-efi-2.02-12.47.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0681-1(SUSE Linux Enterprise Server 12-SP5 ) grub2-x86_64-xen-2.02-12.47.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-common-2.02-90.el8_3.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-debugsource-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-aa64-modules-2.02-90.el8_3.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-ia32-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-ia32-cdboot-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-ia32-modules-2.02-90.el8_3.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-x64-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-x64-cdboot-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-efi-x64-modules-2.02-90.el8_3.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-pc-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-pc-modules-2.02-90.el8_3.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-ppc64le-modules-2.02-90.el8_3.1.noarch.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-tools-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-tools-efi-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-tools-extra-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0696) grub2 security update grub2-tools-minimal-2.02-90.el8_3.1.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-common-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-aa64-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-ia32-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-ia32-cdboot-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-ia32-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-x64-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-x64-cdboot-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-efi-x64-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-pc-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-pc-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-ppc-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-ppc64-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-ppc64le-modules-2.02-0.87.el7_9.2.noarch.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-tools-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-tools-extra-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:0699) grub2 security update grub2-tools-minimal-2.02-0.87.el7_9.2.x86_64.rpm | Linux |
| Grub2 update (ELSA-2021-0699) grub2-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-common update (ELSA-2021-0699) grub2-common-2.02-0.87.0.7.el7_9.2.noarch.rpm | Linux |
| Grub2-efi-ia32 update (ELSA-2021-0699) grub2-efi-ia32-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-efi-ia32-cdboot update (ELSA-2021-0699) grub2-efi-ia32-cdboot-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-efi-ia32-modules update (ELSA-2021-0699) grub2-efi-ia32-modules-2.02-0.87.0.7.el7_9.2.noarch.rpm | Linux |
| Grub2-efi-x64 update (ELSA-2021-0699) grub2-efi-x64-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-efi-x64-cdboot update (ELSA-2021-0699) grub2-efi-x64-cdboot-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-efi-x64-modules update (ELSA-2021-0699) grub2-efi-x64-modules-2.02-0.87.0.7.el7_9.2.noarch.rpm | Linux |
| Grub2-pc update (ELSA-2021-0699) grub2-pc-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-pc-modules update (ELSA-2021-0699) grub2-pc-modules-2.02-0.87.0.7.el7_9.2.noarch.rpm | Linux |
| Grub2-tools update (ELSA-2021-0699) grub2-tools-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-tools-extra update (ELSA-2021-0699) grub2-tools-extra-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| Grub2-tools-minimal update (ELSA-2021-0699) grub2-tools-minimal-2.02-0.87.0.7.el7_9.2.x86_64.rpm | Linux |
| (RHSA-2021:1734) shim security update shim-ia32-15.4-2.el8_1.x86_64.rpm | Linux |
| (RHSA-2021:1734) shim security update shim-x64-15.4-2.el8_1.x86_64.rpm | Linux |
| GRand Unified Bootloader (USN-4992-1) grub-efi-amd64-bin_2.04-1ubuntu44.2_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4992-1) grub-efi-amd64-bin_2.04-1ubuntu44.1.2_i386.deb | Linux |
| GRand Unified Bootloader (USN-4992-1) grub-efi-amd64-bin_2.04-1ubuntu44.1.2_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4992-1) grub-efi-amd64-signed_1.167.2+2.04-1ubuntu44.2_amd64.deb | Linux |
| GRand Unified Bootloader (USN-4992-1) grub-efi-amd64-signed_1.167~18.04.5+2.04-1ubuntu44.1.2_amd64.deb | Linux |
| (RHSA-2021:2566) fwupd security update fwupd-1.5.9-1.el8_4.x86_64.rpm | Linux |
| (RHSA-2021:2566) fwupd security update fwupd-debugsource-1.5.9-1.el8_4.x86_64.rpm | Linux |
| Use After Free Vulnerability (CVE-2020-25632) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234