grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled
Published Mar 3, 2021
7.5
HIGHCVSS 3.1
EPSS 1.74%
Description
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel, defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity, as well as system availability.
Affected products
- Vendor n/a Product Grub2 Defaultn/a
- Version grub 2.06StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Grub2 | n/a |
|
Configuration 2
- 7.0
- 8.0
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 8.2
- 7.6
- 7.7
- 8.1
- 7.4
- 7.6
- 7.7
- 8.2
- 7.0
Configuration 3
- 33
- 34
Configuration 4
- n/a
- n/a
No data.
Red Hat Enterprise Linux 7
grub2-1:2.02-0.87.el7_9.2
Fixed · RHSA-2021:0699
Red Hat Enterprise Linux 7.2 Advanced Update Support
grub2-1:2.02-0.86.el7_2.2
Fixed · RHSA-2021:0704
Red Hat Enterprise Linux 7.3 Advanced Update Support
grub2-1:2.02-0.86.el7_3.2
Fixed · RHSA-2021:0703
Red Hat Enterprise Linux 7.4 Advanced Update Support
grub2-1:2.02-0.86.el7_4.2
Fixed · RHSA-2021:0702
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
grub2-1:2.02-0.86.el7_4.2
Fixed · RHSA-2021:0702
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
grub2-1:2.02-0.86.el7_4.2
Fixed · RHSA-2021:0702
Red Hat Enterprise Linux 7.6 Extended Update Support
grub2-1:2.02-0.86.el7_6.3
Fixed · RHSA-2021:0701
Red Hat Enterprise Linux 7.7 Extended Update Support
grub2-1:2.02-0.86.el7_7.3
Fixed · RHSA-2021:0700
Red Hat Enterprise Linux 8
fwupd-0:1.5.9-1.el8_4
Fixed · RHSA-2021:2566
Red Hat Enterprise Linux 8
grub2-1:2.02-90.el8_3.1
Fixed · RHSA-2021:0696
Red Hat Enterprise Linux 8
shim-0:15.4-2.el8_1
Fixed · RHSA-2021:1734
Red Hat Enterprise Linux 8
shim-unsigned-aarch64-0:15-7.el8_1
Fixed · RHSA-2021:1734
Red Hat Enterprise Linux 8
shim-unsigned-x64-0:15.4-4.el8_1
Fixed · RHSA-2021:1734
Red Hat Enterprise Linux 8.1 Extended Update Support
fwupd-0:1.1.4-4.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.1 Extended Update Support
grub2-1:2.02-87.el8_1.2
Fixed · RHSA-2021:0698
Red Hat Enterprise Linux 8.1 Extended Update Support
shim-0:15.4-2.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.1 Extended Update Support
shim-unsigned-aarch64-0:15-7.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.1 Extended Update Support
shim-unsigned-x64-0:15.4-4.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.2 Extended Update Support
fwupd-0:1.1.4-9.el8_2
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 8.2 Extended Update Support
grub2-1:2.02-87.el8_2.3
Fixed · RHSA-2021:0697
Red Hat Enterprise Linux 8.2 Extended Update Support
shim-0:15.4-2.el8_1
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 8.2 Extended Update Support
shim-unsigned-aarch64-0:15-7.el8_1
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 8.2 Extended Update Support
shim-unsigned-x64-0:15.4-4.el8_1
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 7
fwupd
Affected
Red Hat Enterprise Linux 7
fwupdate
Affected
Red Hat Enterprise Linux 7
shim
Not affected
Red Hat Enterprise Linux 8
fwupdate
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | grub2-1:2.02-0.87.el7_9.2 | Fixed | RHSA-2021:0699 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | grub2-1:2.02-0.86.el7_2.2 | Fixed | RHSA-2021:0704 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | grub2-1:2.02-0.86.el7_3.2 | Fixed | RHSA-2021:0703 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | grub2-1:2.02-0.86.el7_4.2 | Fixed | RHSA-2021:0702 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | grub2-1:2.02-0.86.el7_4.2 | Fixed | RHSA-2021:0702 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | grub2-1:2.02-0.86.el7_4.2 | Fixed | RHSA-2021:0702 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | grub2-1:2.02-0.86.el7_6.3 | Fixed | RHSA-2021:0701 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | grub2-1:2.02-0.86.el7_7.3 | Fixed | RHSA-2021:0700 |
| Red Hat Enterprise Linux 8 | fwupd-0:1.5.9-1.el8_4 | Fixed | RHSA-2021:2566 |
| Red Hat Enterprise Linux 8 | grub2-1:2.02-90.el8_3.1 | Fixed | RHSA-2021:0696 |
| Red Hat Enterprise Linux 8 | shim-0:15.4-2.el8_1 | Fixed | RHSA-2021:1734 |
| Red Hat Enterprise Linux 8 | shim-unsigned-aarch64-0:15-7.el8_1 | Fixed | RHSA-2021:1734 |
| Red Hat Enterprise Linux 8 | shim-unsigned-x64-0:15.4-4.el8_1 | Fixed | RHSA-2021:1734 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | fwupd-0:1.1.4-4.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | grub2-1:2.02-87.el8_1.2 | Fixed | RHSA-2021:0698 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | shim-0:15.4-2.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | shim-unsigned-aarch64-0:15-7.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | shim-unsigned-x64-0:15.4-4.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | fwupd-0:1.1.4-9.el8_2 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | grub2-1:2.02-87.el8_2.3 | Fixed | RHSA-2021:0697 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | shim-0:15.4-2.el8_1 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | shim-unsigned-aarch64-0:15-7.el8_1 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | shim-unsigned-x64-0:15.4-4.el8_1 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 7 | fwupd | Affected | n/a |
| Red Hat Enterprise Linux 7 | fwupdate | Affected | n/a |
| Red Hat Enterprise Linux 7 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | fwupdate | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
For a successful attack to occur, the attacker needs to triage the environment to determine where the lockdown variable symbol is placed in memory when the kernel is loaded. Then the SSDT table needs to be written accordingly into this memory position and the grub.cfg file needs to be changed to load the table during the boot time.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.74% (0.01738) | 76.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.74% (0.01738) | 74.68th | v5 (v2026.06.15) |
| Nov 21, 2025 | 1.30% (0.01299) | 79.11th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.07% (0.04067) | 87.41th | v4 (v2025.03.14) |
| Sep 12, 2025 | 1.21% (0.01210) | 78.25th | v4 (v2025.03.14) |
| Jul 10, 2025 | 2.78% (0.02778) | 85.44th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.12% (0.01118) | 76.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.72% (0.03725) | 79.72th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.12% (0.01118) | 76.25th | v4 (v2025.03.14) |
| Mar 27, 2025 | 3.72% (0.03725) | 86.43th | v4 (v2025.03.14) |
| Mar 20, 2025 | 2.67% (0.02670) | 84.56th | v4 (v2025.03.14) |
| Mar 19, 2025 | 3.72% (0.03725) | 86.60th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.67% (0.02670) | 84.81th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.04% (0.00045) | 14.56th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.04% (0.00045) | 14.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 12.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.67% (0.01669) | 76.02th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.67% (0.01669) | 53.27th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.36% (0.05363) | 79.74th | v1 |
| May 23, 2021 | 5.36% (0.05363) | 0.00th | v1 |
| May 22, 2021 | 1.25% (0.01247) | 0.00th | v5 (v2026.06.15) |
| Apr 16, 2021 | 0.83% (0.00833) | 0.00th | v1 |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (8)
- https://access.redhat.com/security/cve/CVE-2020-14372 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2021-003 x_refsource_MISCPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1873150 x_refsource_MISCIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-14372
- https://security.gentoo.org/glsa/202104-05 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210416-0004/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-14372
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-14372 | Vendor Advisory | |
| https://access.redhat.com/security/vulnerabilities/RHSB-2021-003 | x_refsource_MISCPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1873150 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-14372 | ||
| https://security.gentoo.org/glsa/202104-05 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20210416-0004/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-14372 |
Change history (0)
No recorded changes yet.