[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-1048Date: (C)2024-02-08   (M)2024-06-07


A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 3.3CVSS Score :
Exploit Score: 1.8Exploit Score:
Impact Score: 1.4Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: LOWAuthentication:
User Interaction: NONEConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: NONEAvailability:
Integrity: NONE 
Availability: LOW 
  
Reference:
RHBZ#2256827
RHSA-2024:2456
RHSA-2024:3184
http://www.openwall.com/lists/oss-security/2024/02/06/3
https://access.redhat.com/security/cve/CVE-2024-1048
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XRZQCVZ3XOASVFT6XLO7F2ZXOLOHIJZQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/
https://security.netapp.com/advisory/ntap-20240223-0007/
https://www.openwall.com/lists/oss-security/2024/02/06/3

CWE    1
CWE-459
OVAL    8
oval:org.secpod.oval:def:19500635
oval:org.secpod.oval:def:509286
oval:org.secpod.oval:def:1702203
oval:org.secpod.oval:def:127339
...

© SecPod Technologies