Описание
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
rear | fixed | 2.7+dfsg-1.2 | package | |
rear | no-dsa | bookworm | package | |
rear | no-dsa | bullseye | package |
Примечания
https://github.com/rear/rear/issues/3122
https://github.com/rear/rear/pull/3123
https://github.com/rear/rear/commit/89b61793d80bc2cb2abe47a7d0549466fb087d16
EPSS
Связанные уязвимости
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
EPSS