grub2: Use-after-free in rmmod command
Published Mar 3, 2021
8.2
HIGHCVSS 3.1
EPSS 1.15%
Description
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected products
- Vendor n/a Product Grub2 Defaultunknown
Affected
- grub 2.06
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Grub2 | unknown | Affected
|
Configuration 2
- 7.0
- 8.0
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 8.2
- 7.6
- 7.7
- 8.1
- 7.4
- 7.6
- 7.7
- 8.2
- 7.0
Configuration 3
- 33
- 34
Configuration 4
- n/a
No data.
Red Hat Enterprise Linux 7
grub2-1:2.02-0.87.el7_9.2
Fixed · RHSA-2021:0699
Red Hat Enterprise Linux 7.2 Advanced Update Support
grub2-1:2.02-0.86.el7_2.2
Fixed · RHSA-2021:0704
Red Hat Enterprise Linux 7.3 Advanced Update Support
grub2-1:2.02-0.86.el7_3.2
Fixed · RHSA-2021:0703
Red Hat Enterprise Linux 7.4 Advanced Update Support
grub2-1:2.02-0.86.el7_4.2
Fixed · RHSA-2021:0702
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
grub2-1:2.02-0.86.el7_4.2
Fixed · RHSA-2021:0702
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
grub2-1:2.02-0.86.el7_4.2
Fixed · RHSA-2021:0702
Red Hat Enterprise Linux 7.6 Extended Update Support
grub2-1:2.02-0.86.el7_6.3
Fixed · RHSA-2021:0701
Red Hat Enterprise Linux 7.7 Extended Update Support
grub2-1:2.02-0.86.el7_7.3
Fixed · RHSA-2021:0700
Red Hat Enterprise Linux 8
fwupd-0:1.5.9-1.el8_4
Fixed · RHSA-2021:2566
Red Hat Enterprise Linux 8
grub2-1:2.02-90.el8_3.1
Fixed · RHSA-2021:0696
Red Hat Enterprise Linux 8
shim-0:15.4-2.el8_1
Fixed · RHSA-2021:1734
Red Hat Enterprise Linux 8
shim-unsigned-aarch64-0:15-7.el8_1
Fixed · RHSA-2021:1734
Red Hat Enterprise Linux 8
shim-unsigned-x64-0:15.4-4.el8_1
Fixed · RHSA-2021:1734
Red Hat Enterprise Linux 8.1 Extended Update Support
fwupd-0:1.1.4-4.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.1 Extended Update Support
grub2-1:2.02-87.el8_1.2
Fixed · RHSA-2021:0698
Red Hat Enterprise Linux 8.1 Extended Update Support
shim-0:15.4-2.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.1 Extended Update Support
shim-unsigned-aarch64-0:15-7.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.1 Extended Update Support
shim-unsigned-x64-0:15.4-4.el8_1
Fixed · RHSA-2021:3675
Red Hat Enterprise Linux 8.2 Extended Update Support
fwupd-0:1.1.4-9.el8_2
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 8.2 Extended Update Support
grub2-1:2.02-87.el8_2.3
Fixed · RHSA-2021:0697
Red Hat Enterprise Linux 8.2 Extended Update Support
shim-0:15.4-2.el8_1
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 8.2 Extended Update Support
shim-unsigned-aarch64-0:15-7.el8_1
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 8.2 Extended Update Support
shim-unsigned-x64-0:15.4-4.el8_1
Fixed · RHSA-2021:2790
Red Hat Enterprise Linux 7
fwupd
Affected
Red Hat Enterprise Linux 7
fwupdate
Affected
Red Hat Enterprise Linux 7
shim
Not affected
Red Hat Enterprise Linux 8
fwupdate
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | grub2-1:2.02-0.87.el7_9.2 | Fixed | RHSA-2021:0699 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | grub2-1:2.02-0.86.el7_2.2 | Fixed | RHSA-2021:0704 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | grub2-1:2.02-0.86.el7_3.2 | Fixed | RHSA-2021:0703 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | grub2-1:2.02-0.86.el7_4.2 | Fixed | RHSA-2021:0702 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | grub2-1:2.02-0.86.el7_4.2 | Fixed | RHSA-2021:0702 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | grub2-1:2.02-0.86.el7_4.2 | Fixed | RHSA-2021:0702 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | grub2-1:2.02-0.86.el7_6.3 | Fixed | RHSA-2021:0701 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | grub2-1:2.02-0.86.el7_7.3 | Fixed | RHSA-2021:0700 |
| Red Hat Enterprise Linux 8 | fwupd-0:1.5.9-1.el8_4 | Fixed | RHSA-2021:2566 |
| Red Hat Enterprise Linux 8 | grub2-1:2.02-90.el8_3.1 | Fixed | RHSA-2021:0696 |
| Red Hat Enterprise Linux 8 | shim-0:15.4-2.el8_1 | Fixed | RHSA-2021:1734 |
| Red Hat Enterprise Linux 8 | shim-unsigned-aarch64-0:15-7.el8_1 | Fixed | RHSA-2021:1734 |
| Red Hat Enterprise Linux 8 | shim-unsigned-x64-0:15.4-4.el8_1 | Fixed | RHSA-2021:1734 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | fwupd-0:1.1.4-4.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | grub2-1:2.02-87.el8_1.2 | Fixed | RHSA-2021:0698 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | shim-0:15.4-2.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | shim-unsigned-aarch64-0:15-7.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | shim-unsigned-x64-0:15.4-4.el8_1 | Fixed | RHSA-2021:3675 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | fwupd-0:1.1.4-9.el8_2 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | grub2-1:2.02-87.el8_2.3 | Fixed | RHSA-2021:0697 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | shim-0:15.4-2.el8_1 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | shim-unsigned-aarch64-0:15-7.el8_1 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | shim-unsigned-x64-0:15.4-4.el8_1 | Fixed | RHSA-2021:2790 |
| Red Hat Enterprise Linux 7 | fwupd | Affected | n/a |
| Red Hat Enterprise Linux 7 | fwupdate | Affected | n/a |
| Red Hat Enterprise Linux 7 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | fwupdate | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-25632 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1879577 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-18303 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-25632
- https://security.gentoo.org/glsa/202104-05 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220325-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25632
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-25632 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1879577 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-18303 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWZ36QK4IKU6MWDWNOOWKPH3WXZBHT2R/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-25632 | ||
| https://security.gentoo.org/glsa/202104-05 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20220325-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-25632 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data