CVE-2015-5281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
24/11/2015
Last modified:
12/04/2025

Description

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*