CVE-2020-26541

Aliases:UBUNTU-CVE-2020-26541DEBIAN-CVE-2020-26541
Modified
Published: 02 Oct 2020, 18:14
Last modified:04 Aug 2024, 15:56

Vulnerability Summary

Overall Risk (default)
medium
38/100
CVSS Score
6.9 MEDIUM
v2.0 (nvd)
EPSS Score
0.53% LOW
1% probability +0.41%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

02 Oct 2020, 18:14
Published
Vulnerability first disclosed
04 Aug 2024, 15:56
Last Modified
Vulnerability information updated

Description

The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AC:L/AV:L/A:H/C:H/I:H/PR:H/S:U/UI:R
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.53% Percentile: 44%

Affected Systems

  • debianlinux

    < 5.10.70-1 | < 5.14.6-1 | < 5.14.6-1 | < 5.14.6-1

  • ubuntulinux

    all | < 5.4.0-92.103

  • ubuntulinux-aws

    all | < 5.4.0-1061.64

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    < 5.11.0-1017.18~20.04.1

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1061.64~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-fips

    all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | < 5.4.0-1065.68

  • ubuntulinux-azure-4.15

    all

  • ubuntulinux-azure-5.11

    < 5.11.0-1015.16~20.04.1

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1065.68~18.04.1

  • ubuntulinux-azure-5.8

    < 5.8.0-1043.46~20.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fips

    all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1023.26

  • ubuntulinux-fips

    all | < 5.4.0-1038.44

  • ubuntulinux-gcp

    all | all | < 5.4.0-1059.63

  • ubuntulinux-gcp-4.15

    all

  • ubuntulinux-gcp-5.11

    < 5.11.0-1018.20~20.04.2

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1059.63~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke

    < 5.4.0-1057.60

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1057.60~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1029.30

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1029.30~18.04.2

  • ubuntulinux-hwe

    all | all

  • ubuntulinux-hwe-5.11

    < 5.11.0-34.36~20.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-92.103~18.04.2

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-ibm

    < 5.4.0-1010.11

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    all | < 5.4.0-1051.53

  • ubuntulinux-lts-xenial

    all

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1049.51

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    all | < 5.4.0-1059.63

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.11

    < 5.11.0-1017.18~20.04.1

  • ubuntulinux-oracle-5.3

    all

Showing first 50 affected entries in server-rendered view.

References (12)