DSN-2021-002: Dell Response to the March 2, 2021 Grub2 Vulnerability Disclosure
Summary: Dell is aware of the vulnerabilities in Grand Unified Bootloader (GRUB)
Security Article Type
Security KB
CVE Identifier
CVE-2020-14372, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-2023
Issue Summary
Grand Unified Bootloader (GRUB) vulnerability disclosure on March 2, 2021.
Details
Dell is aware of the vulnerabilities in Grand Unified Bootloader (GRUB) disclosed on March 2, 2021.
The security of our products is critical to helping ensure our customers’ data and systems are protected.See the following security advisories for remediation instructions regarding impacted products:
Dell Storage Products
- Powerflex Rack: DSA-2021-065
- VxRail: DSA-2021-090 and DSA-2021-098
- Data Protection Central: DSA-2021-093
- Dell EMC SRM: DSA-2021-135
- Cloud Tiering Appliance: DSA-2021-140
- Avamar: DSA-2021-141
- Data Protection Search: DSA-2021-147
- IDPA ACM: DSA-2021-203
*Note: Any non-security updates or configuration changes required to support updates released by Operating System providers will be communicated via product-specific technical support articles.
Recommendations
Dell recommends that customers review their Operating System provider’s advisories for further information, including appropriate identification and mitigation measures.
- Debian https://www.debian.org/security/2021-GRUB-UEFI-SecureBoot
- Red Hat https://access.redhat.com/security/vulnerabilities/RHSB-2021-003
- SUSE https://www.suse.com/support/kb/doc/?id=000019892
- Canonical https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass2021
Note: Links to other Operating System provider advisories are listed above as they are available.
See the following technical support articles which provide additional information and context as it relates to Dell products:
- Dell Client Platforms https://www.dell.com/support/kbdoc/000183697
- Dell EMC PowerEdge Servers https://www.dell.com/support/kbdoc/000184338
Note: Links to other technical support articles for Dell products will be provided as they are available.