CWE
416 362
Advisory Published
CVE Published
CVE Published
Updated

CVE-2020-15706: GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing.

First published: Mon Jul 27 2020(Updated: )

"grub2 contains a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing."

Credit: security@ubuntu.com

Affected SoftwareAffected VersionHow to fix
redhat/fwupdate<0:12-6.el7_8
0:12-6.el7_8
redhat/grub2<1:2.02-0.86.el7_8
1:2.02-0.86.el7_8
redhat/shim<0:15-7.el7_9
0:15-7.el7_9
redhat/shim-signed<0:15-7.el7_8
0:15-7.el7_8
redhat/grub2<1:2.02-0.86.el7_2
1:2.02-0.86.el7_2
redhat/shim<0:15-8.el7
0:15-8.el7
redhat/shim-signed<0:15-8.el7_2
0:15-8.el7_2
redhat/grub2<1:2.02-0.86.el7
1:2.02-0.86.el7
redhat/shim-signed<0:15-8.el7_3
0:15-8.el7_3
redhat/fwupdate<0:9-10.el7_4
0:9-10.el7_4
redhat/grub2<1:2.02-0.86.el7_4
1:2.02-0.86.el7_4
redhat/shim-signed<0:15-8.el7_4
0:15-8.el7_4
redhat/fwupdate<0:12-6.el7_6
0:12-6.el7_6
redhat/grub2<1:2.02-0.86.el7_6
1:2.02-0.86.el7_6
redhat/shim-signed<0:15-8.el7_6
0:15-8.el7_6
redhat/fwupdate<0:12-6.el7_7
0:12-6.el7_7
redhat/grub2<1:2.02-0.86.el7_7
1:2.02-0.86.el7_7
redhat/shim-signed<0:15-8.el7_7
0:15-8.el7_7
redhat/fwupd<0:1.1.4-7.el8_2
0:1.1.4-7.el8_2
redhat/grub2<1:2.02-87.el8_2
1:2.02-87.el8_2
redhat/shim<0:15-14.el8_2
0:15-14.el8_2
redhat/shim-unsigned-x64<0:15-7.el8
0:15-7.el8
redhat/fwupd<0:1.1.4-2.el8_0
0:1.1.4-2.el8_0
redhat/grub2<1:2.02-87.el8_0
1:2.02-87.el8_0
redhat/shim<0:15-14.el8_0
0:15-14.el8_0
redhat/fwupd<0:1.1.4-2.el8_1
0:1.1.4-2.el8_1
redhat/grub2<1:2.02-87.el8_1
1:2.02-87.el8_1
redhat/shim<0:15-14.el8_1
0:15-14.el8_1
redhat/grub<2.06
2.06
debian/grub2
2.06-3~deb11u6
2.06-13+deb12u1
2.12-5
GRUB 2<=2.04
Red Hat Enterprise Linux Atomic Host
redhat openshift container platform=4.0
Ubuntu Linux=14.04
Ubuntu Linux=16.04
Ubuntu Linux=18.04
Ubuntu Linux=20.04
Debian GNU/Linux=10.0
Red Hat Enterprise Linux=7.0
Red Hat Enterprise Linux=8.0
SUSE Linux Enterprise Server=11
SUSE Linux Enterprise Server=12
SUSE Linux Enterprise Server=15
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 8.1
Microsoft Windows RT
Microsoft Windows Server 2012 x64
Microsoft Windows Server 2012 x64=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=1903
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
openSUSE=15.1
openSUSE=15.2
Ubuntu Linux=16.04
Ubuntu=14.04
Ubuntu=16.04
Ubuntu=18.04
Ubuntu=20.04
Debian=10.0
Ubuntu=16.04

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the severity of CVE-2020-15706?

    CVE-2020-15706 is rated as a medium severity vulnerability due to the potential for exploitation leading to use-after-free conditions.

  • How do I fix CVE-2020-15706?

    To remediate CVE-2020-15706, update to the patched versions of grub2, shim, and other affected packages as specified by your Linux distribution.

  • Which affected software versions are impacted by CVE-2020-15706?

    CVE-2020-15706 impacts several versions of grub2, fwupdate, shim, and shim-signed on Red Hat and other Linux distributions.

  • What type of vulnerability is CVE-2020-15706?

    CVE-2020-15706 is a use-after-free vulnerability caused by a race condition in the grub_script_function_create() function.

  • Who is affected by CVE-2020-15706?

    Users of affected versions of grub2 and related packages on Red Hat and other Linux distributions are at risk from CVE-2020-15706.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203