CVE-2020-14311 PUBLISHED

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

EPSS 0.03% · 9.1th percentile

Risk Scores

EPSS Score
0.03%
9.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSgrub20, *, *
Ubuntu:16.04:LTSgrub22.02~beta2-36ubuntu3.14, *, *
Ubuntu:20.04:LTSgrub22.04-1ubuntu12, 2.04-1ubuntu16, 2.04-1ubuntu14
Ubuntu:16.04:LTSgrub2-unsigned2.04-1ubuntu44.1.2, 2.04-1ubuntu44.1, 2.04-1ubuntu44
Ubuntu:16.04:LTSgrub2-signed1.66.6, 1.66.2, 1.66.1
Ubuntu:20.04:LTSgrub2-unsigned2.04-1ubuntu44, 2.04-1ubuntu44.2, 0
Ubuntu:18.04:LTSgrub2-signed1.93.4, 1.93.3, 1.93.2
Ubuntu:Pro:14.04:LTSgrub2-signed1.25, 1.27, 1.34.20
Ubuntu:20.04:LTSgrub2-signed1.142.1, 1.130, 1.128
Ubuntu:18.04:LTSgrub22.02-2ubuntu6, 2.02-2ubuntu2, 2.02-2ubuntu1
Ubuntu:18.04:LTSgrub2-unsigned2.04-1ubuntu44.1, 2.04-1ubuntu44.1.2, 2.04-1ubuntu44

Timeline

References

Open in Interactive Console →