Wind River Support Network

HomeDefectsLINCD-2723
Fixed

LINCD-2723 : Security Advisory - grub - CVE-2020-14308

Created: Jul 29, 2020    Updated: Sep 13, 2022
Resolved Date: Nov 16, 2020
Found In Version: 10.20.6.0
Fix Version: 10.20.48.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Userspace

Description

In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process.

CREATE(Triage):(User=admin) CVE-2020-14308 (https://nvd.nist.gov/vuln/detail/CVE-2020-14308)

CVEs


Live chat
Online