CVE-2020-15705

MEDIUM

GRUB2 < 2.04 - Secure Boot Bypass via Improper Cryptographic Signature Verification

Title source: llm
STIX 2.1

Description

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

References (20)

Core 20
Core References
Third Party Advisory x_refsource_confirm
https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://ubuntu.com/security/notices/USN-4432-1
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot
Patch, Third Party Advisory, Vendor Advisory x_refsource_confirm
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/security/vulnerabilities/grub2bootloader
Third Party Advisory vendor-advisory x_refsource_suse
https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/
Third Party Advisory vendor-advisory x_refsource_suse
https://www.suse.com/support/kb/doc/?id=000019673
Mailing List, Third Party Advisory x_refsource_confirm
https://www.openwall.com/lists/oss-security/2020/07/29/3
Issue Tracking, Vendor Advisory x_refsource_confirm
https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/07/29/3
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200731-0008/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4432-1/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/03/02/3
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202104-05
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/09/17/2
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/09/17/4
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/09/21/1

Scores

CVSS v3 6.4
EPSS 0.0002
EPSS Percentile 6.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (32)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
debian/debian_linux 10.0
gnu/grub2 < 2.04
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1709
microsoft/windows_10 1803
... and 22 more
Published Jul 29, 2020
Tracked Since Feb 18, 2026