Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14309
HistoryJul 29, 2020 - 5:06 p.m.

CVE-2020-14309

2020-07-2917:06:12
redhat.com
access.redhat.com
17

0.001 Low

EPSS

Percentile

19.0%

A flaw was found in grub2. When handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size, the name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.