Recently, the security research company Eclypsium released a new "BootHole" vulnerability, which affects most Linux distributions and Windows devices using the GRUB2 boot loader with Secure Boot.
Since GRUB2 is the most popular and widely used boot loader in Linux distributions, systems are now vulnerable to attack. Even when Secure Boot is enabled, attackers can gain near total control of the victim's device.
However, the attack can be launched in very limited situations where attackers must have root access to edit the GRUB2 configuration file. Now, to mitigate the BootHole vulnerability, operating systems using GRUB2 with Secure Boot need new signed installers and boot loaders.
Linux distributions respond to BootHole
Fortunately, Eclypsium has already coordinated responsibly with major Linux and OEM vendors. Therefore, in response to BootHole, Red Hat security teams have released security fixes for its several affected products and are still in progress for others.
Debian developers are also aware of BootHole and perform a thorough audit of the source code of GRUB2. Since Debian 10 "buster" was the first release of Debian to include support for UEFI Secure Boot, the security team has targeted all fixes in the upcoming 10.5 release on August 1, 2020.
Marcus Meissner, Head of the SUSE Security Team, informed that SUSE has also released new grub2 packages that fix the BootHole vulnerability for all SUSE Linux products. Along with this, it also released the corresponding Linux kernel packages, cloud images, and installation media updates.
Speaking of the most popular Linux distributions, Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, and 20.04 LTS also have received updates for the GRUB2 2.06 boot loader from the Canonical Security Team.
To go further, the team also discovered seven other vulnerabilities, including CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706, and CVE-2020-15707.
So if you are using any of these Linux distributions with the GRUB2 boot loader, you need to update your system, especially the GRUB2 packages, as provided by the distribution maintainers. For other Linux distributions, new fixes will be coming soon.
