Upstream information

CVE-2015-5281 at MITRE

Description

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

CVSS v2 Scores
  National Vulnerability Database
Base Score 2.6
Vector AV:L/AC:H/Au:N/C:P/I:P/A:N
Access Vector Local
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 7
  • grub2 >= 2.02-0.29.el7
  • grub2-efi >= 2.02-0.29.el7
  • grub2-efi-modules >= 2.02-0.29.el7
  • grub2-tools >= 2.02-0.29.el7
Patchnames:
RHSA-2015:2401


SUSE Timeline for this CVE

CVE page created: Tue Nov 17 06:39:02 2015
CVE page last modified: Mon Oct 30 17:17:41 2023