CVE Vulnerabilities

CVE-2019-14865

Privilege Defined With Unsafe Actions

Published: Nov 29, 2019 | Modified: Feb 06, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

Name Vendor Start Version End Version
Grub2 Gnu - (including) - (including)
Red Hat Enterprise Linux 8 RedHat grub2-1:2.02-78.el8_1.1 *
Grub2 Ubuntu trusty *

Potential Mitigations

References