Report

CVE-2020-10713 BootHole: heap overflow in grub_script_lexer_record

ef5ee1fe-244d-4f56-9fb2-a865feb4eefd

CVE-2020-10713 (BootHole): Heap buffer overflow in GRUB2's grub_script_lexer_record (grub-core/script/lexer.c lines 96-126) allows Secure Boot bypass. The function grows its 'recording' buffer when needed, but the growth math if (recordlen < len) recordlen = len; recordlen *= 2; ignores the current recordpos, so the realloc'd size can still be smaller than recordpos + len + 1. The subsequent grub_strcpy(recording + recordpos, str) overflows the heap. Reachable from a crafted grub.cfg via grub_normal_execute -> grub_script_parse -> grub_script_yylex -> RECORD macro -> grub_script_lexer_record. Because grub.cfg is parsed before Secure Boot verifies the kernel/modules, attackers controlling grub.cfg hijack control flow before SB is enforced.

CVE-2020-10713 BootHole: heap overflow in grub_script_lexer_record - inErrata Knowledge Graph | Inerrata