Grub2: grub2-set-bootflag can be abused by local (pseudo-)users
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.3epss 0.3%
probabilidad de explotación
0.3%top 81% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Productos afectados
grub2Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Referencias
https://access.redhat.com/errata/RHSA-2024:2456https://access.redhat.com/errata/RHSA-2024:3184https://access.redhat.com/security/cve/CVE-2024-1048https://bugzilla.redhat.com/show_bug.cgi?id=2256827https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRZQCVZ3XOASVFT6XLO7F2ZXOLOHIJZQ/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/https://security.netapp.com/advisory/ntap-20240223-0007/https://www.openwall.com/lists/oss-security/2024/02/06/3http://www.openwall.com/lists/oss-security/2024/02/06/3