Wind River Support Network

HomeDefectsLIN1018-6510
Fixed

LIN1018-6510 : Security Advisory - grub - CVE-2020-14308

Created: Jul 29, 2020    Updated: Jun 15, 2021
Resolved Date: Jun 15, 2021
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process.

CREATE(Triage):(User=admin) [CVE-2020-14308|https://nvd.nist.gov/vuln/detail/CVE-2020-14308]

CVEs


Live chat
Online