Rapid7 Vulnerability & Exploit Database

Centos Linux: CVE-2020-15705: Moderate: grub2 security update (Multiple Advisories)

Back to Search

Centos Linux: CVE-2020-15705: Moderate: grub2 security update (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
07/29/2020
Created
07/31/2020
Added
07/30/2020
Modified
08/05/2020

Description

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

Solution(s)

  • centos-upgrade-fwupd
  • centos-upgrade-fwupd-debuginfo
  • centos-upgrade-fwupd-debugsource
  • centos-upgrade-fwupdate
  • centos-upgrade-fwupdate-debuginfo
  • centos-upgrade-fwupdate-devel
  • centos-upgrade-fwupdate-efi
  • centos-upgrade-fwupdate-libs
  • centos-upgrade-grub2
  • centos-upgrade-grub2-common
  • centos-upgrade-grub2-debuginfo
  • centos-upgrade-grub2-debugsource
  • centos-upgrade-grub2-efi-aa64-modules
  • centos-upgrade-grub2-efi-ia32
  • centos-upgrade-grub2-efi-ia32-cdboot
  • centos-upgrade-grub2-efi-ia32-modules
  • centos-upgrade-grub2-efi-x64
  • centos-upgrade-grub2-efi-x64-cdboot
  • centos-upgrade-grub2-efi-x64-modules
  • centos-upgrade-grub2-pc
  • centos-upgrade-grub2-pc-modules
  • centos-upgrade-grub2-ppc-modules
  • centos-upgrade-grub2-ppc64-modules
  • centos-upgrade-grub2-ppc64le-modules
  • centos-upgrade-grub2-tools
  • centos-upgrade-grub2-tools-debuginfo
  • centos-upgrade-grub2-tools-efi
  • centos-upgrade-grub2-tools-efi-debuginfo
  • centos-upgrade-grub2-tools-extra
  • centos-upgrade-grub2-tools-extra-debuginfo
  • centos-upgrade-grub2-tools-minimal
  • centos-upgrade-grub2-tools-minimal-debuginfo
  • centos-upgrade-mokutil
  • centos-upgrade-mokutil-debuginfo
  • centos-upgrade-shim-ia32
  • centos-upgrade-shim-unsigned-ia32
  • centos-upgrade-shim-unsigned-x64
  • centos-upgrade-shim-x64

References

  • centos-upgrade-fwupd
  • centos-upgrade-fwupd-debuginfo
  • centos-upgrade-fwupd-debugsource
  • centos-upgrade-fwupdate
  • centos-upgrade-fwupdate-debuginfo
  • centos-upgrade-fwupdate-devel
  • centos-upgrade-fwupdate-efi
  • centos-upgrade-fwupdate-libs
  • centos-upgrade-grub2
  • centos-upgrade-grub2-common
  • centos-upgrade-grub2-debuginfo
  • centos-upgrade-grub2-debugsource
  • centos-upgrade-grub2-efi-aa64-modules
  • centos-upgrade-grub2-efi-ia32
  • centos-upgrade-grub2-efi-ia32-cdboot
  • centos-upgrade-grub2-efi-ia32-modules
  • centos-upgrade-grub2-efi-x64
  • centos-upgrade-grub2-efi-x64-cdboot
  • centos-upgrade-grub2-efi-x64-modules
  • centos-upgrade-grub2-pc
  • centos-upgrade-grub2-pc-modules
  • centos-upgrade-grub2-ppc-modules
  • centos-upgrade-grub2-ppc64-modules
  • centos-upgrade-grub2-ppc64le-modules
  • centos-upgrade-grub2-tools
  • centos-upgrade-grub2-tools-debuginfo
  • centos-upgrade-grub2-tools-efi
  • centos-upgrade-grub2-tools-efi-debuginfo
  • centos-upgrade-grub2-tools-extra
  • centos-upgrade-grub2-tools-extra-debuginfo
  • centos-upgrade-grub2-tools-minimal
  • centos-upgrade-grub2-tools-minimal-debuginfo
  • centos-upgrade-mokutil
  • centos-upgrade-mokutil-debuginfo
  • centos-upgrade-shim-ia32
  • centos-upgrade-shim-unsigned-ia32
  • centos-upgrade-shim-unsigned-x64
  • centos-upgrade-shim-x64

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;