REDHAT-BUG-2345865: Use After Free
In some scenarios hooks created by loaded modules are not being removed when the related module is being unloaded. An attacker may leverage this by forcing the grub2 to call the hooks once the module which registered it was unloaded, leading to a Use-after-free vulnerability. If correctly exploited this vulnerability may result in Arbitrary Code Execution eventually allowing the attacker to by-pass secure boot protections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2345865?
The severity of REDHAT-BUG-2345865 is critical due to the potential for a Use-after-free vulnerability.
How do I fix REDHAT-BUG-2345865?
To fix REDHAT-BUG-2345865, ensure you apply the latest patches or updates provided by the GNU GRUB2 maintainers.
What causes the vulnerability in REDHAT-BUG-2345865?
The vulnerability in REDHAT-BUG-2345865 is caused by hooks created by loaded modules not being removed when the related module is unloaded.
Who is affected by REDHAT-BUG-2345865?
Users of GNU GRUB2 are affected by REDHAT-BUG-2345865.
What are the potential consequences of exploiting REDHAT-BUG-2345865?
Exploiting REDHAT-BUG-2345865 can lead to arbitrary code execution and further compromise of the system.