Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15705

Опубликовано: 29 июл. 2020
Источник: redhat
CVSS3: 6.4

Описание

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-440
https://bugzilla.redhat.com/show_bug.cgi?id=1860978grub2: Fail kernel validation without shim protocol

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
больше 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
nvd
больше 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 6.4
debian
больше 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without ...

suse-cvrf
около 5 лет назад

Security update for grub2

6.4 Medium

CVSS3