The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
Grub2 | Ubuntu | precise | * |
Grub2 | Ubuntu | vivid | * |
Grub2 | Ubuntu | wily | * |
Grub2 | Ubuntu | yakkety | * |
Red Hat Enterprise Linux 7 | RedHat | grub2-1:2.02-0.29.el7 | * |