CVE-2020-25632: Fedoraproject Fedora
High severity, CVSS 8.2. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected products
- Fedoraproject Fedora: version 33 only; version 34 only
- GNU GRUB2: before 2.06 (fixed in 2.06)
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Enterprise Linux Server Aus: version 7.2 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only; version 8.2 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only; version 7.7 only; version 8.1 only
- Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only; version 7.7 only; version 8.2 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2021-03-03. Last modified 2026-06-17.