CVE-2015-5281: Red Hat Enterprise Linux
Low severity, CVSS 2.6. EPSS: 0.3% chance of exploitation in the next 30 days.
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.
Affected products
- Red Hat Enterprise Linux: version 7.0 only
Published 2015-11-24. Last modified 2026-06-17.