CVE-2020-27749 was backported to dunfell in 636aab87bc7e10b4ce0bdaa00dd01416a590a801. However, grub is building corrupt binaries in at least some cases now. I have seen this with a custom xen_pvh. GCC puts some of terminate_arg() into terminate_arg.cold() in a .text.unlikely section. In the final linked binary, .text.unlikely is ordered ahead of .text. When the entry point is called, it jumps to the incorrect terminate_arg.cold instead of _start. The situation is similar to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14367, AFAICT. The bug there was traced to the same change, but the particular issue was not identified. I have confirmed that the CFLAGS_remove = "-O2" fixes the issue in dunfell. The other workaround is to add CFLAGS_append = "-fno-reorder-functions" to prevent the use of .text.unlikely. I think dunfell should cherry-pick https://github.com/openembedded/openembedded-core/commit/69805629b8f47fd46a37b7c5cc435982e2ac3d1d to resolve the issue. That keeps dunfell in line with other OE branches. Thanks!
Fixed: https://git.yoctoproject.org/poky/commit/?h=dunfell&id=b1fdc92450ba1f3869116d88bd92a5a75b8e9f87