Zero-Day GRUB2 Vulnerability Hits Linux Users, Patch Available for Ubuntu, RHEL

53

According to Canonical’a latest Ubuntu Security Notice, it would appear that there’s a zero-day security vulnerability in the GRUB2 (GNU GRand Unified Bootloader) packages, affecting all GNU/Linux distributions running 2.02 Beta.

The security flaw was discovered by developers Ismael Ripoll and Hector Marco in the upstream GRUB2 packages, which did not correctly handled the backspace key when the bootloader was configured to use password-protected authentication, thus allowing a local attacker to bypass GRUB’s password protection.