Insecure Inherited Permissions in grub - CVE-2021-3981

 

Insecure Inherited Permissions in grub - CVE-2021-3981

Published: June 14, 2022


Vulnerability identifier: #VU64272
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3981
CWE-ID: CWE-277
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to incorrect default permissions for in grub.cfg file that are set by the application. A local user with access to the system can view contents of files and directories.


Affected software

grub
Gentoo Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
Fedora
OpenShift Service Mesh
shim-signed (Ubuntu package)
grub-efi-amd64-signed (Ubuntu package)
grub-efi-arm64-signed (Ubuntu package)
grub2 (Red Hat package)
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-aa64
grub2-efi-aa64-cdboot
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2
grub2-debugsource
grub2-debuginfo
grub2-help
sys-boot/grub
grub-efi-arm64-bin (Ubuntu package)
grub-efi-arm64 (Ubuntu package)
grub-efi-amd64-bin (Ubuntu package)
grub-efi-amd64 (Ubuntu package)
shim (Ubuntu package)

How to mitigate CVE-2021-3981

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

OpenShift Service Mesh - update to 2.1.3
shim-signed (Ubuntu package) - addressed in versions 1.40.9+15.7-0ubuntu1, 1.51.3+15.7-0ubuntu1
grub-efi-amd64-signed (Ubuntu package) - addressed in versions 1.187.3~20.04.1+2.06-2ubuntu14.1, 1.187.3~22.04.1+2.06-2ubuntu14.1
grub-efi-arm64-signed (Ubuntu package) - addressed in versions 1.187.3~20.04.1+2.06-2ubuntu14.1, 1.187.3~22.04.1+2.06-2ubuntu14.1
grub2 (Red Hat package) - update to 2.02-123.el8
grub2-tools-efi - update to 2.02-123.0.1
grub2-common - update to 2.02-123.0.1
grub2-efi-aa64-modules - update to 2.02-123.0.1
grub2-efi-ia32-modules - update to 2.02-123.0.1
grub2-efi-x64-modules - update to 2.02-123.0.1
grub2-pc-modules - update to 2.02-123.0.1
grub2-efi-aa64 - update to 2.02-123.0.1
grub2-efi-aa64-cdboot - update to 2.02-123.0.1
grub2-tools - update to 2.02-123.0.1
grub2-tools-extra - update to 2.02-123.0.1
grub2-tools-minimal - update to 2.02-123.0.1
grub2-efi-ia32 - update to 2.02-123.0.1
grub2-efi-ia32-cdboot - update to 2.02-123.0.1
grub2-efi-x64 - update to 2.02-123.0.1
grub2-efi-x64-cdboot - update to 2.02-123.0.1
grub2-pc - update to 2.02-123.0.1
grub2-efi-ia32 - update to 2.04-23
grub2-tools-efi - update to 2.04-23
grub2-efi-ia32-cdboot - update to 2.04-23
grub2-efi-aa64-modules - update to 2.04-23
grub2-efi-x64-cdboot - update to 2.04-23
grub2-efi-x64 - update to 2.04-23
grub2 - update to 2.04-23
grub2-efi-aa64-cdboot - update to 2.04-23
grub2-tools - update to 2.04-23
grub2-debugsource - update to 2.04-23
grub2-efi-aa64 - update to 2.04-23
grub2-tools-minimal - update to 2.04-23
grub2-tools-extra - update to 2.04-23
grub2-debuginfo - update to 2.04-23
grub2-efi-x64-modules - update to 2.04-23
grub2-help - update to 2.04-23
grub2-common - update to 2.04-23
grub2-efi-ia32-modules - update to 2.04-23
grub2-pc-modules - update to 2.04-23
grub2-pc - update to 2.04-23
sys-boot/grub - update to 2.06
grub-efi-arm64-bin (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-arm64 (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-amd64-bin (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-amd64 (Ubuntu package) - update to 2.06-2ubuntu14.1
grub2 - addressed in versions 2.06-8.fc34, 2.06-9.fc34, 2.06-9.fc35, 2.06-10.fc35
grub2 - update to 2.06-61
shim (Ubuntu package) - update to 15.7-0ubuntu1

External References

Related Security Bulletins