#VU51193 Stack-based buffer overflow in grub - CVE-2020-27749
Published: March 3, 2021 / Updated: December 17, 2024
grub
GNU
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the grub_parser_split_cmdline() function while expanding variable names present in the supplied command line in to their corresponding variable contents. A local privileged user can run a specially crafted program to trigger the stack-based buffer overflow and bypass Secure Boot protection.