Описание
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
A flaw was found in GRUB2. GRUB2 do not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving the UEFI system table hooks after exit. This issue leads to a use-after-free condition, possibly leading to a secure boot bypass.
Отчет
This flaw is specific to Debian/Ubuntu and derived distributions. GRUB2 as shipped in Red Hat Enterprise Linux does not include the peimage module. Therefore, Red Hat Products are not affected by this issue.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | grub2 | Not affected | ||
| Red Hat Enterprise Linux 7 | grub2 | Not affected | ||
| Red Hat Enterprise Linux 8 | grub2 | Not affected | ||
| Red Hat Enterprise Linux 9 | grub2 | Not affected |
Показывать по
Дополнительная информация
Статус:
6.7 Medium
CVSS3
Связанные уязвимости
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
GRUB2 does not call the module fini functions on exit, leading to Debi ...
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.
6.7 Medium
CVSS3