CVE-2020-14308
Summary
| CVE | CVE-2020-14308 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-29 20:15:00 UTC |
| Updated | 2022-04-18 15:22:00 UTC |
| Description | In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - multiple secure boot grub2 and linux kernel vulnerabilities | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| oss-security - Re: Containers-optimized OS (COS) membership in the linux-distros list | MLIST | www.openwall.com | |
| July 2020 Grub2 Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| oss-security - Re: Containers-optimized OS (COS) membership in the linux-distros list | MLIST | www.openwall.com | |
| [security-announce] openSUSE-SU-2020:1168-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2020:1169-1: important: Security update | SUSE | lists.opensuse.org | |
| GRUB: Multiple vulnerabilities (GLSA 202104-05) — Gentoo security | GENTOO | security.gentoo.org | |
| USN-4432-1: GRUB 2 vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| 1852009 – (CVE-2020-14308) CVE-2020-14308 grub2: grub_malloc does not validate allocation size allowing for arithmetic overflow and subsequent heap-based buffer overflow | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| oss-security - Containers-optimized OS (COS) membership in the linux-distros list | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377345 Alibaba Cloud Linux Security Update for grub2 (ALINUX3-SA-2022:0064)
- 377367 Alibaba Cloud Linux Security Update for grub2 (ALINUX3-SA-2021:0026)
- 377533 Alibaba Cloud Linux Security Update for grub2 (ALINUX2-SA-2020:0108)
- 502730 Alpine Linux Security Update for grub
- 710015 Gentoo Linux GRUB Multiple Vulnerabilities (GLSA 202104-05)
- 900056 CBL-Mariner Linux Security Update for grub2 2.06~rc1
- 901826 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (6456-1)
- 903304 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (1825)
- 905953 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (1825-1)
- 906325 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (6456-2)