CVE-2020-15706: Canonical Ubuntu Linux

Medium severity, CVSS 6.4. EPSS: 1% chance of exploitation in the next 30 days.

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 10.0 only
  • GNU GRUB2: up to and including 2.04
  • Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
  • Microsoft Windows 8.1: affected versions not specified
  • Microsoft Windows Rt 8.1: affected versions not specified
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only
  • Microsoft Windows Server 2016: affected versions not specified; version 1903 only; version 1909 only; version 2004 only
  • Microsoft Windows Server 2019: affected versions not specified
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Atomic Host: affected versions not specified
  • Red Hat Openshift Container Platform: version 4.0 only
  • Suse Suse Linux Enterprise Server: version 11 only; version 12 only; version 15 only

Published 2020-07-29. Last modified 2026-06-17.