Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-1048

Опубликовано: 06 фев. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.3

Описание

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

does not affect Secure Boot
esm-infra-legacy/trusty

not-affected

does not affect Secure Boot
esm-infra/bionic

not-affected

does not affect Secure Boot
esm-infra/focal

not-affected

does not affect Secure Boot
esm-infra/xenial

not-affected

does not affect Secure Boot
focal

not-affected

does not affect Secure Boot
jammy

not-affected

does not affect Secure Boot
mantic

not-affected

does not affect Secure Boot
noble

not-affected

does not affect Secure Boot

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

RH specific
esm-infra-legacy/trusty

not-affected

RH specific
esm-infra/bionic

not-affected

RH specific
esm-infra/focal

not-affected

RH specific
esm-infra/xenial

not-affected

RH specific
focal

not-affected

RH specific
jammy

not-affected

RH specific
mantic

not-affected

RH specific
noble

not-affected

RH specific

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

RH specific
esm-infra/bionic

not-affected

RH specific
esm-infra/focal

not-affected

RH specific
esm-infra/xenial

not-affected

RH specific
focal

not-affected

RH specific
jammy

not-affected

RH specific
mantic

not-affected

RH specific
noble

not-affected

RH specific
oracular

not-affected

RH specific

Показывать по

EPSS

Процентиль: 1%
0.00013
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
redhat
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.3
nvd
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.3
debian
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the ...

CVSS3: 3.2
github
больше 1 года назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.3
fstec
больше 1 года назад

Уязвимость загрузчика операционных систем Grub2, связанная с неполной очисткой временных или вспомогательных ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 1%
0.00013
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2024-1048