Related Vulnerabilities: CVE-2020-25632  

The rmmod implementation for grub2 is flawed, allowing an attacker to unload a module used as a dependency without checking if any other dependent module is still loaded. This leads to a use-after-free scenario possibly allowing an attacker to execute arbitrary code and by-pass Secure Boot protections.

Severity Medium

Remote No

Type Arbitrary code execution

Description

The rmmod implementation for grub2 is flawed, allowing an attacker to unload a module used as a dependency without checking if any other dependent module is still loaded. This leads to a use-after-free scenario possibly allowing an attacker to execute arbitrary code and by-pass Secure Boot protections.

AVG-1629 grub 2:2.04-10 2:2.04.r340.g8fcfd1e0f-1 Medium Testing

https://lists.gnu.org/archive/html/grub-devel/2021-03/msg00007.html