Wind River Support Network

HomeDefectsLIN10-7599
Fixed

LIN10-7599 : Security Advisory - grub - CVE-2020-14308

Created: Jul 29, 2020    Updated: May 30, 2021
Resolved Date: May 30, 2021
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process.

CREATE(Triage):(User=admin) [CVE-2020-14308|https://nvd.nist.gov/vuln/detail/CVE-2020-14308]

CVEs


Live chat
Online