
Recently, researchers at Eclypsium discovered the new “BootHole” Bug, which affects all operating systems that use the GRUB2 bootloader with Secure Boot.
Today, almost all different Linux distributions, as well as many Windows devices , use the GRUB2 bootloader. According to researchers, hackers can gain almost complete access to these devices, regardless of the secure boot option.
However, to gain access to systems, hackers must first gain administrative privileges to make changes to the Bootloader config. Sure, even though they need administrative privileges, the “BootHole” remains a serious problem that affects a large percentage of users.
Therefore, many companies are already working with Eclypsium to remove the “BootHole” from future distributions. Other companies, such as Red Hat, have already announced some security fixes for their products.

Meanwhile, the Debian development team is performing a full code review of the GRUB2 bootloader. Since Debian 10 “buster” is the first release to include UEFI Secure Boot, the team wants to improve the operating system’s bootloader before the release of version 10.5, which is due in early August.
In addition to the Debian development team, the SUSE Linux team has also made several improvements to the GRUB2 bootloader. According to Marcus Meissner, the “BootHole” bug has already been removed from all SUSE Linux. In addition, the distributions contain other improvements, for example, updates to the kernel packages.
Of course, all the major Linux distributions have already been updated. For example, Canonical has announced improved versions of Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, and 20.04 LTS.
In addition to the “BootHole” bug, Eclypsium researchers also discovered several other vulnerabilities, known as CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706 and CVE-2020-15707. For the same reason, the vulnerable distribution groups recommend that users immediately update their operating systems to avoid future attacks.
