Resource management error in grub2 - CVE-2024-1048
Published: March 6, 2024
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the grub2-set-bootflag utility of grub2. The grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
Affected software
grub2-efi-loongarch64-cdboot
grub2-efi-aa64
grub2-efi-aa64-cdboot
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-loongarch64
grub2 (Red Hat package)
grub2-debugsource
grub2-debuginfo
grub2-help
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Fedora
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
OpenShift Service Mesh
How to mitigate CVE-2024-1048
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
grub2-efi-loongarch64-cdboot - update to 2.02-150.0.2
grub2-efi-aa64 - update to 2.02-150.0.2
grub2-efi-aa64-cdboot - update to 2.02-150.0.2
grub2-tools - update to 2.02-150.0.2
grub2-tools-extra - update to 2.02-150.0.2
grub2-tools-minimal - update to 2.02-150.0.2
grub2-efi-ia32 - update to 2.02-150.0.2
grub2-efi-ia32-cdboot - update to 2.02-150.0.2
grub2-efi-x64 - update to 2.02-150.0.2
grub2-efi-x64-cdboot - update to 2.02-150.0.2
grub2-pc - update to 2.02-150.0.2
grub2-tools-efi - update to 2.02-150.0.2
grub2-common - update to 2.02-150.0.2
grub2-efi-aa64-modules - update to 2.02-150.0.2
grub2-efi-ia32-modules - update to 2.02-150.0.2
grub2-efi-x64-modules - update to 2.02-150.0.2
grub2-pc-modules - update to 2.02-150.0.2
grub2-efi-loongarch64 - update to 2.02-150.0.2
grub2 (Red Hat package) - addressed in versions 2.02-156.el8, 2.06-77.el9
grub2-efi-ia32-cdboot - update to 2.04-32
grub2-tools-efi - update to 2.04-32
grub2-efi-ia32 - update to 2.04-32
grub2-pc - update to 2.04-32
grub2-efi-x64 - update to 2.04-32
grub2-efi-x64-cdboot - update to 2.04-32
grub2 - update to 2.04-32
grub2-tools-minimal - update to 2.04-32
grub2-efi-aa64-cdboot - update to 2.04-32
grub2-tools - update to 2.04-32
grub2-efi-aa64 - update to 2.04-32
grub2-debugsource - update to 2.04-32
grub2-tools-extra - update to 2.04-32
grub2-debuginfo - update to 2.04-32
grub2-efi-x64-modules - update to 2.04-32
grub2-efi-ia32-modules - update to 2.04-32
grub2-help - update to 2.04-32
grub2-pc-modules - update to 2.04-32
grub2-efi-aa64-modules - update to 2.04-32
grub2-common - update to 2.04-32
OpenShift Service Mesh - update to 2.5.2
grub2 - update to 2.06-61
External References
Related Security Bulletins
- Fedora 39 update for grub2
- Fedora 38 update for grub2
- Red Hat Enterprise Linux 9 update for grub2
- Red Hat Enterprise Linux 8 update for grub2
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in IBM Qradar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Amazon Linux AMI update for grub2
- openEuler update for grub2
- Anolis OS update for grub2