The rmmod implementation for grub2 is flawed, allowing an attacker to unload a module used as dependency without checking if any other dependent module is still loaded. This leads to an use-after-free scenario possibly allowing an attacker to execute arbitrary code and by-pass Secure Boot protections.
Marking fwupdate as WONTFIX for all rhel8 streams. This package was made obsolete and replaced by fwupd.
Created grub2 tracking bugs for this issue: Affects: fedora-all [bug 1934246]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2021:0698 https://access.redhat.com/errata/RHSA-2021:0698
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:0696 https://access.redhat.com/errata/RHSA-2021:0696
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2021:0697 https://access.redhat.com/errata/RHSA-2021:0697
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.3 Advanced Update Support Via RHSA-2021:0703 https://access.redhat.com/errata/RHSA-2021:0703
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.2 Advanced Update Support Via RHSA-2021:0704 https://access.redhat.com/errata/RHSA-2021:0704
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.4 Advanced Update Support Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions Red Hat Enterprise Linux 7.4 Telco Extended Update Support Via RHSA-2021:0702 https://access.redhat.com/errata/RHSA-2021:0702
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:0699 https://access.redhat.com/errata/RHSA-2021:0699
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.7 Extended Update Support Via RHSA-2021:0700 https://access.redhat.com/errata/RHSA-2021:0700
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.6 Extended Update Support Via RHSA-2021:0701 https://access.redhat.com/errata/RHSA-2021:0701
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-25632
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1734 https://access.redhat.com/errata/RHSA-2021:1734
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:2566 https://access.redhat.com/errata/RHSA-2021:2566
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2021:2790 https://access.redhat.com/errata/RHSA-2021:2790
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2021:3675 https://access.redhat.com/errata/RHSA-2021:3675