CVE-2024-1048

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:grub2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

History

21 Mar 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/ -

11 Mar 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRZQCVZ3XOASVFT6XLO7F2ZXOLOHIJZQ/ -

23 Feb 2024, 16:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240223-0007/ -

13 Feb 2024, 21:22

Type Values Removed Values Added
CPE cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:a:gnu:grub2:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
References () http://www.openwall.com/lists/oss-security/2024/02/06/3 - () http://www.openwall.com/lists/oss-security/2024/02/06/3 - Mailing List, Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2024-1048 - () https://access.redhat.com/security/cve/CVE-2024-1048 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2256827 - () https://bugzilla.redhat.com/show_bug.cgi?id=2256827 - Issue Tracking, Vendor Advisory
References () https://www.openwall.com/lists/oss-security/2024/02/06/3 - () https://www.openwall.com/lists/oss-security/2024/02/06/3 - Mailing List, Third Party Advisory
First Time Redhat enterprise Linux
Fedoraproject
Redhat
Gnu
Gnu grub2
Fedoraproject fedora
Summary
  • (es) Se encontró una falla en la utilidad grub2-set-bootflag de grub2. Después de la corrección de CVE-2019-14865, grub2-set-bootflag creará un archivo temporal con el nuevo contenido de grubenv y le cambiará el nombre al archivo grubenv original. Si el programa se elimina antes de la operación de cambio de nombre, el archivo temporal no se eliminará y puede llenar el sistema de archivos cuando se invoque varias veces, lo que resultará en un sistema de archivos sin inodos o bloques libres.

06 Feb 2024, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.2
v2 : unknown
v3 : 3.3
CWE CWE-459

06 Feb 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-06 18:15

Updated : 2024-03-21 03:15


NVD link : CVE-2024-1048

Mitre link : CVE-2024-1048

CVE.ORG link : CVE-2024-1048


JSON object : View

Products Affected

redhat

  • enterprise_linux

gnu

  • grub2

fedoraproject

  • fedora
CWE
CWE-459

Incomplete Cleanup