Medium severity6.4NVD Advisory· Published Jul 29, 2020· Updated Jun 17, 2026
CVE-2020-15705
CVE-2020-15705
Description
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31- osv-coords29 versionspkg:rpm/opensuse/grub2&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/grub2&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/grub2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/grub2&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/grub2&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/grub2&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/grub2&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/grub2&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/grub2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/grub2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 2.02-lp151.21.27.1+ 28 more
- (no CPE)range: < 2.02-lp151.21.27.1
- (no CPE)range: < 2.04-lp152.7.9.1
- (no CPE)range: < 2.06-7.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-19.56.1
- (no CPE)range: < 2.02-19.56.1
- (no CPE)range: < 2.02-26.33.1
- (no CPE)range: < 2.04-9.15.1
- (no CPE)range: < 2.02-26.33.1
- (no CPE)range: < 2.04-9.15.1
- (no CPE)range: < 2.00-0.66.21.1
- (no CPE)range: < 2.02~beta2-115.56.1
- (no CPE)range: < 2.02~beta2-115.56.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-12.39.1
- (no CPE)range: < 2.02-12.39.1
- (no CPE)range: < 2.02-19.56.1
- (no CPE)range: < 2.02~beta2-115.56.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-12.39.1
- (no CPE)range: < 2.02-12.39.1
- (no CPE)range: < 2.02-19.56.1
- (no CPE)range: < 2.02~beta2-115.56.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-12.39.1
- (no CPE)range: < 2.02-4.61.1
- (no CPE)range: < 2.02-12.39.1
- Ubuntu/grub2 in Ubuntuv5Range: 20.04 LTS
Patches
Vulnerability mechanics
References
20- portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011nvdPatchThird Party AdvisoryVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.htmlnvdMailing ListThird Party Advisory
- ubuntu.com/security/notices/USN-4432-1nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2020/07/29/3nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/03/02/3nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/09/17/2nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/09/17/4nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/09/21/1nvdMailing ListThird Party Advisory
- access.redhat.com/security/vulnerabilities/grub2bootloadernvdThird Party Advisory
- lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.htmlnvdIssue TrackingVendor Advisory
- security.gentoo.org/glsa/202104-05nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20200731-0008/nvdThird Party Advisory
- usn.ubuntu.com/4432-1/nvdThird Party Advisory
- wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypassnvdThird Party Advisory
- www.debian.org/security/2020-GRUB-UEFI-SecureBootnvdThird Party Advisory
- www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2020/07/29/3nvdMailing ListThird Party Advisory
- www.suse.com/c/suse-addresses-grub2-secure-boot-issue/nvdThird Party Advisory
- www.suse.com/support/kb/doc/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.