Insecure Inherited Permissions in grub - CVE-2021-3981
Published: June 14, 2022
Vulnerability identifier: #VU64272
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3981
CWE-ID: CWE-277
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect default permissions for in grub.cfg file that are set by the application. A local user with access to the system can view contents of files and directories.
Affected software
grub
Gentoo Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
Fedora
OpenShift Service Mesh
shim-signed (Ubuntu package)
grub-efi-amd64-signed (Ubuntu package)
grub-efi-arm64-signed (Ubuntu package)
grub2 (Red Hat package)
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-aa64
grub2-efi-aa64-cdboot
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2
grub2-debugsource
grub2-debuginfo
grub2-help
sys-boot/grub
grub-efi-arm64-bin (Ubuntu package)
grub-efi-arm64 (Ubuntu package)
grub-efi-amd64-bin (Ubuntu package)
grub-efi-amd64 (Ubuntu package)
shim (Ubuntu package)
Gentoo Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
Fedora
OpenShift Service Mesh
shim-signed (Ubuntu package)
grub-efi-amd64-signed (Ubuntu package)
grub-efi-arm64-signed (Ubuntu package)
grub2 (Red Hat package)
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-aa64
grub2-efi-aa64-cdboot
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2
grub2-debugsource
grub2-debuginfo
grub2-help
sys-boot/grub
grub-efi-arm64-bin (Ubuntu package)
grub-efi-arm64 (Ubuntu package)
grub-efi-amd64-bin (Ubuntu package)
grub-efi-amd64 (Ubuntu package)
shim (Ubuntu package)
How to mitigate CVE-2021-3981
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
OpenShift Service Mesh - update to 2.1.3
shim-signed (Ubuntu package) - addressed in versions 1.40.9+15.7-0ubuntu1, 1.51.3+15.7-0ubuntu1
grub-efi-amd64-signed (Ubuntu package) - addressed in versions 1.187.3~20.04.1+2.06-2ubuntu14.1, 1.187.3~22.04.1+2.06-2ubuntu14.1
grub-efi-arm64-signed (Ubuntu package) - addressed in versions 1.187.3~20.04.1+2.06-2ubuntu14.1, 1.187.3~22.04.1+2.06-2ubuntu14.1
grub2 (Red Hat package) - update to 2.02-123.el8
grub2-tools-efi - update to 2.02-123.0.1
grub2-common - update to 2.02-123.0.1
grub2-efi-aa64-modules - update to 2.02-123.0.1
grub2-efi-ia32-modules - update to 2.02-123.0.1
grub2-efi-x64-modules - update to 2.02-123.0.1
grub2-pc-modules - update to 2.02-123.0.1
grub2-efi-aa64 - update to 2.02-123.0.1
grub2-efi-aa64-cdboot - update to 2.02-123.0.1
grub2-tools - update to 2.02-123.0.1
grub2-tools-extra - update to 2.02-123.0.1
grub2-tools-minimal - update to 2.02-123.0.1
grub2-efi-ia32 - update to 2.02-123.0.1
grub2-efi-ia32-cdboot - update to 2.02-123.0.1
grub2-efi-x64 - update to 2.02-123.0.1
grub2-efi-x64-cdboot - update to 2.02-123.0.1
grub2-pc - update to 2.02-123.0.1
grub2-efi-ia32 - update to 2.04-23
grub2-tools-efi - update to 2.04-23
grub2-efi-ia32-cdboot - update to 2.04-23
grub2-efi-aa64-modules - update to 2.04-23
grub2-efi-x64-cdboot - update to 2.04-23
grub2-efi-x64 - update to 2.04-23
grub2 - update to 2.04-23
grub2-efi-aa64-cdboot - update to 2.04-23
grub2-tools - update to 2.04-23
grub2-debugsource - update to 2.04-23
grub2-efi-aa64 - update to 2.04-23
grub2-tools-minimal - update to 2.04-23
grub2-tools-extra - update to 2.04-23
grub2-debuginfo - update to 2.04-23
grub2-efi-x64-modules - update to 2.04-23
grub2-help - update to 2.04-23
grub2-common - update to 2.04-23
grub2-efi-ia32-modules - update to 2.04-23
grub2-pc-modules - update to 2.04-23
grub2-pc - update to 2.04-23
sys-boot/grub - update to 2.06
grub-efi-arm64-bin (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-arm64 (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-amd64-bin (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-amd64 (Ubuntu package) - update to 2.06-2ubuntu14.1
grub2 - addressed in versions 2.06-8.fc34, 2.06-9.fc34, 2.06-9.fc35, 2.06-10.fc35
grub2 - update to 2.06-61
shim (Ubuntu package) - update to 15.7-0ubuntu1
shim-signed (Ubuntu package) - addressed in versions 1.40.9+15.7-0ubuntu1, 1.51.3+15.7-0ubuntu1
grub-efi-amd64-signed (Ubuntu package) - addressed in versions 1.187.3~20.04.1+2.06-2ubuntu14.1, 1.187.3~22.04.1+2.06-2ubuntu14.1
grub-efi-arm64-signed (Ubuntu package) - addressed in versions 1.187.3~20.04.1+2.06-2ubuntu14.1, 1.187.3~22.04.1+2.06-2ubuntu14.1
grub2 (Red Hat package) - update to 2.02-123.el8
grub2-tools-efi - update to 2.02-123.0.1
grub2-common - update to 2.02-123.0.1
grub2-efi-aa64-modules - update to 2.02-123.0.1
grub2-efi-ia32-modules - update to 2.02-123.0.1
grub2-efi-x64-modules - update to 2.02-123.0.1
grub2-pc-modules - update to 2.02-123.0.1
grub2-efi-aa64 - update to 2.02-123.0.1
grub2-efi-aa64-cdboot - update to 2.02-123.0.1
grub2-tools - update to 2.02-123.0.1
grub2-tools-extra - update to 2.02-123.0.1
grub2-tools-minimal - update to 2.02-123.0.1
grub2-efi-ia32 - update to 2.02-123.0.1
grub2-efi-ia32-cdboot - update to 2.02-123.0.1
grub2-efi-x64 - update to 2.02-123.0.1
grub2-efi-x64-cdboot - update to 2.02-123.0.1
grub2-pc - update to 2.02-123.0.1
grub2-efi-ia32 - update to 2.04-23
grub2-tools-efi - update to 2.04-23
grub2-efi-ia32-cdboot - update to 2.04-23
grub2-efi-aa64-modules - update to 2.04-23
grub2-efi-x64-cdboot - update to 2.04-23
grub2-efi-x64 - update to 2.04-23
grub2 - update to 2.04-23
grub2-efi-aa64-cdboot - update to 2.04-23
grub2-tools - update to 2.04-23
grub2-debugsource - update to 2.04-23
grub2-efi-aa64 - update to 2.04-23
grub2-tools-minimal - update to 2.04-23
grub2-tools-extra - update to 2.04-23
grub2-debuginfo - update to 2.04-23
grub2-efi-x64-modules - update to 2.04-23
grub2-help - update to 2.04-23
grub2-common - update to 2.04-23
grub2-efi-ia32-modules - update to 2.04-23
grub2-pc-modules - update to 2.04-23
grub2-pc - update to 2.04-23
sys-boot/grub - update to 2.06
grub-efi-arm64-bin (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-arm64 (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-amd64-bin (Ubuntu package) - update to 2.06-2ubuntu14.1
grub-efi-amd64 (Ubuntu package) - update to 2.06-2ubuntu14.1
grub2 - addressed in versions 2.06-8.fc34, 2.06-9.fc34, 2.06-9.fc35, 2.06-10.fc35
grub2 - update to 2.06-61
shim (Ubuntu package) - update to 15.7-0ubuntu1
External References
Related Security Bulletins
- Incorrect default permissions in GNU grub
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.1
- Gentoo update for GRUB
- Red Hat Enterprise Linux 8 update for grub2
- Ubuntu update for grub2-signed
- openEuler update for grub2
- Amazon Linux AMI update for grub2
- Fedora 35 update for grub2
- Fedora 34 update for grub2
- Fedora 35 update for grub2
- Fedora 34 update for grub2
- Anolis OS update for grub2