Incorrect default permissions in Relax-and-Recover - CVE-2024-23301

 

Incorrect default permissions in Relax-and-Recover - CVE-2024-23301

Published: January 23, 2024


Vulnerability identifier: #VU85736
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23301
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to software creates a world-readable initrd when using GRUB_RESCUE=y. A local user with access to the system can gain access to system secrets otherwise only readable by root.


Affected software

Relax-and-Recover
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Availability Extension 12
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
SUSE Linux Enterprise Server 15 SP1 Business Critical Linux
SUSE Linux Enterprise Server 15 SP2 Business Critical Linux
SUSE Linux Enterprise Server 15 SP3 Business Critical Linux
openSUSE Leap
openEuler
Fedora
rear116
rear1172a
rear118a
rear23a
rear-help
rear
rear (Red Hat package)
rear-doc
rear27a

How to mitigate CVE-2024-23301

Install update from vendor's website.

rear116 - update to 1.16-15.3.1
rear1172a - update to 1.17.2.a-5.3.1
rear118a - update to 1.18.a-9.3.1
rear23a - addressed in versions 2.3.a-3.9.1, 2.3.a-150000.9.9.1, 2.3.a-150300.21.3.1
rear-help - update to 2.4-5
rear - update to 2.4-5
rear (Red Hat package) - addressed in versions 2.6-11.el8_9, 2.6-21.el9_3
rear-doc - update to 2.6-12.0.1
rear - update to 2.6-12.0.1
rear - addressed in versions 2.7-8.fc38, 2.7-8.fc39
rear27a - addressed in versions 2.7-8.6.1, 2.7-150200.5.6.1, 2.7-150500.3.3.1

External References

Related Security Bulletins