CVE-2020-15706: Canonical Ubuntu Linux
Medium severity, CVSS 6.4. EPSS: 1% chance of exploitation in the next 30 days.
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 10.0 only
- GNU GRUB2: up to and including 2.04
- Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
- Microsoft Windows 8.1: affected versions not specified
- Microsoft Windows Rt 8.1: affected versions not specified
- Microsoft Windows Server 2012: affected versions not specified; version r2 only
- Microsoft Windows Server 2016: affected versions not specified; version 1903 only; version 1909 only; version 2004 only
- Microsoft Windows Server 2019: affected versions not specified
- Opensuse Leap: version 15.1 only; version 15.2 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Enterprise Linux Atomic Host: affected versions not specified
- Red Hat Openshift Container Platform: version 4.0 only
- Suse Suse Linux Enterprise Server: version 11 only; version 12 only; version 15 only
Published 2020-07-29. Last modified 2026-06-17.