Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1048

Опубликовано: 06 фев. 2024
Источник: redhat
CVSS3: 3.3

Описание

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

Отчет

The grub2-set-bootflag utility is a command line tool to set a bootflag in the GRUB environment block. This is a downstream utility and is shipped only in Red Hat Enterprise Linux 8 and 9.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6grubNot affected
Red Hat Enterprise Linux 7grub2Not affected
Red Hat Enterprise Linux 8grub2FixedRHSA-2024:318422.05.2024
Red Hat Enterprise Linux 9grub2FixedRHSA-2024:245630.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-459
https://bugzilla.redhat.com/show_bug.cgi?id=2256827grub2: grub2-set-bootflag can be abused by local (pseudo-)users

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.3
nvd
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.3
debian
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the ...

CVSS3: 3.2
github
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.3
fstec
больше 1 года назад

Уязвимость загрузчика операционных систем Grub2, связанная с неполной очисткой временных или вспомогательных ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3