CVE-2020-14309: Buffer Overflow
A flaw was found in grub2. When handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size, the name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Integer overflow in grubsquashreadsymlink triggered by a specially crafted squashfs filesystem containing a symlink inode with a name length of UINT32, which leads to a zero-sized allocation and subsequent heap buffer overflow with attacker controlled data.
— Red Hat
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14309?
CVE-2020-14309 is a vulnerability in grub2 that allows for a heap-based buffer overflow with attacker controlled data.
How severe is CVE-2020-14309?
CVE-2020-14309 has a severity rating of 6.7, which is considered medium severity.
Which software versions are affected by CVE-2020-14309?
Grub2 versions before 2.06 are affected by CVE-2020-14309.
What is the remedy for CVE-2020-14309?
The remedy for CVE-2020-14309 is to update affected software versions to version 2.06.
Where can I find more information about CVE-2020-14309?
You can find more information about CVE-2020-14309 on the Red Hat Security Advisory page (RHSA-2020:3216) and the CVE page (CVE-2020-14309).