CVE-2021-3981

A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

History

16 Jan 2024, 01:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/01/15/3 -

12 Feb 2023, 23:43

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:2110', 'name': 'https://access.redhat.com/errata/RHSA-2022:2110', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2021-3981', 'name': 'https://access.redhat.com/security/cve/CVE-2021-3981', 'tags': [], 'refsource': 'MISC'}
Summary A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.

02 Feb 2023, 21:21

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AI776L35DDYPCSAAJPJM3ZEQYSFZHBJX/', 'name': 'FEDORA-2021-73d63662b0', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • (MISC) https://access.redhat.com/errata/RHSA-2022:2110 -
  • (MISC) https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AI776L35DDYPCSAAJPJM3ZEQYSFZHBJX/ -
  • (MISC) https://access.redhat.com/security/cve/CVE-2021-3981 -
Summary A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released. A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg.

28 Oct 2022, 13:22

Type Values Removed Values Added
References (GENTOO) https://security.gentoo.org/glsa/202209-12 - (GENTOO) https://security.gentoo.org/glsa/202209-12 - Third Party Advisory

25 Sep 2022, 16:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202209-12 -

14 Mar 2022, 23:47

Type Values Removed Values Added
CPE cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 3.3
First Time Gnu
Gnu grub2
Fedoraproject fedora
Fedoraproject
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AI776L35DDYPCSAAJPJM3ZEQYSFZHBJX/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AI776L35DDYPCSAAJPJM3ZEQYSFZHBJX/ - Mailing List, Third Party Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2024170 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2024170 - Issue Tracking, Patch, Third Party Advisory

10 Mar 2022, 17:54

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-10 17:43

Updated : 2024-01-16 01:15


NVD link : CVE-2021-3981

Mitre link : CVE-2021-3981

CVE.ORG link : CVE-2021-3981


JSON object : View

Products Affected

gnu

  • grub2

fedoraproject

  • fedora
CWE
CWE-276

Incorrect Default Permissions