CVE-2020-15707: Canonical Ubuntu Linux
Medium severity, CVSS 6.4. EPSS: 1.6% chance of exploitation in the next 30 days.
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 10.0 only
- GNU GRUB2: up to and including 2.04
- Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
- Microsoft Windows 8.1: affected versions not specified
- Microsoft Windows Rt 8.1: affected versions not specified
- Microsoft Windows Server 2012: affected versions not specified; version r2 only
- Microsoft Windows Server 2016: affected versions not specified; version 1903 only; version 1909 only; version 2004 only
- Microsoft Windows Server 2019: affected versions not specified
- Netapp Active Iq Unified Manager: from 9.5
- Opensuse Leap: version 15.1 only; version 15.2 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Enterprise Linux Atomic Host: affected versions not specified
- Red Hat Openshift Container Platform: version 4.0 only
- Suse Suse Linux Enterprise Server: version 11 only; version 12 only; version 15 only
Published 2020-07-29. Last modified 2026-06-17.