CVE-2020-25632: Fedoraproject Fedora

High severity, CVSS 8.2. EPSS: 1.2% chance of exploitation in the next 30 days.

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products

  • Fedoraproject Fedora: version 33 only; version 34 only
  • GNU GRUB2: before 2.06 (fixed in 2.06)
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only; version 8.2 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only; version 7.7 only; version 8.1 only
  • Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only; version 7.7 only; version 8.2 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2021-03-03. Last modified 2026-06-17.