VDB

ALPINE-CVE-2020-14311

ALPINE-CVE-2020-14311 PUBLISHED CVSS 6 MEDIUM

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

Risk Scores

CVSS v3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.17grub2.04-r3, 0, 2.02-r0
Alpine:v3.19grub0, 2.02-r0, 2.02-r1
Alpine:v3.20grub2.02_beta3-r1, 2.02-r0, 2.02-r8
Alpine:v3.21grub0, 2.04-r3, 2.04-r2
Alpine:v3.23grub2.02-r17, 0, 2.02-r0
Alpine:v3.22grub2.04-r3, 2.04-r2, 2.04-r1
Alpine:v3.18grub0, 2.02-r0, 2.02-r1

Timeline

  • Jul 31, 2020 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›