Security Advisory

CVE-2020-14311

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-07-31 20:56:30
Last updated 2024-08-04 12:39:36
Assigner redhat
CVSS score 5.7
State PUBLISHED

Description

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.