Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15706

Опубликовано: 29 июл. 2020
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS2: 4.4
CVSS3: 6.4

Описание

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

РелизСтатусПримечание
bionic

released

2.02-2ubuntu8.16
devel

not-affected

2.06-2ubuntu18
esm-infra-legacy/trusty

released

2.02~beta2-9ubuntu1.20
esm-infra-legacy/xenial

released

2.02~beta2-36ubuntu3.26
esm-infra/bionic

released

2.02-2ubuntu8.16
esm-infra/focal

released

2.04-1ubuntu26.1
esm-infra/xenial

released

2.02~beta2-36ubuntu3.26
focal

released

2.04-1ubuntu26.1
groovy

not-affected

2.04-1ubuntu26.1
hirsute

not-affected

2.04-1ubuntu26.1

Показывать по

РелизСтатусПримечание
bionic

released

1.93.18
devel

not-affected

1.193
esm-infra-legacy/trusty

released

1.34.22
esm-infra-legacy/xenial

released

1.66.26
esm-infra/bionic

released

1.93.18
esm-infra/focal

released

1.142.3
esm-infra/xenial

released

1.66.26
focal

released

1.142.3
groovy

not-affected

1.147
hirsute

not-affected

1.147

Показывать по

РелизСтатусПримечание
bionic

not-affected

2.04-1ubuntu47.4
devel

not-affected

2.06-2ubuntu17
esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

needed

esm-infra/bionic

not-affected

2.04-1ubuntu47.4
esm-infra/focal

not-affected

2.04-1ubuntu47.4
esm-infra/xenial

ignored

end of ESM support, was needed
focal

not-affected

2.04-1ubuntu47.4
jammy

not-affected

2.06-2ubuntu10
kinetic

not-affected

2.06-2ubuntu12

Показывать по

EPSS

Процентиль: 59%
0.00977
Низкий

4.4 Medium

CVSS2

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
redhat
около 6 лет назад

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
nvd
около 6 лет назад

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
msrc
почти 6 лет назад

GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing.

CVSS3: 6.4
debian
около 6 лет назад

GRUB2 contains a race condition in grub_script_function_create() leadi ...

CVSS3: 6.4
github
около 4 лет назад

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

EPSS

Процентиль: 59%
0.00977
Низкий

4.4 Medium

CVSS2

6.4 Medium

CVSS3