A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Grub2 | Gnu | - (including) | - (including) |
Red Hat Enterprise Linux 8 | RedHat | grub2-1:2.02-78.el8_1.1 | * |
Grub2 | Ubuntu | trusty | * |