Resource management error in grub2 - CVE-2024-1048

 

Resource management error in grub2 - CVE-2024-1048

Published: March 6, 2024


Vulnerability identifier: #VU87164
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-1048
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in the grub2-set-bootflag utility of grub2. The grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.


Affected software

grub2
grub2-efi-loongarch64-cdboot
grub2-efi-aa64
grub2-efi-aa64-cdboot
grub2-tools
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-loongarch64
grub2 (Red Hat package)
grub2-debugsource
grub2-debuginfo
grub2-help
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Fedora
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
OpenShift Service Mesh

How to mitigate CVE-2024-1048

Install updates from vendor's website.

grub2 - addressed in versions 2.06-118.fc39, 2.06-115.fc38, 2.06-117.fc39
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
grub2-efi-loongarch64-cdboot - update to 2.02-150.0.2
grub2-efi-aa64 - update to 2.02-150.0.2
grub2-efi-aa64-cdboot - update to 2.02-150.0.2
grub2-tools - update to 2.02-150.0.2
grub2-tools-extra - update to 2.02-150.0.2
grub2-tools-minimal - update to 2.02-150.0.2
grub2-efi-ia32 - update to 2.02-150.0.2
grub2-efi-ia32-cdboot - update to 2.02-150.0.2
grub2-efi-x64 - update to 2.02-150.0.2
grub2-efi-x64-cdboot - update to 2.02-150.0.2
grub2-pc - update to 2.02-150.0.2
grub2-tools-efi - update to 2.02-150.0.2
grub2-common - update to 2.02-150.0.2
grub2-efi-aa64-modules - update to 2.02-150.0.2
grub2-efi-ia32-modules - update to 2.02-150.0.2
grub2-efi-x64-modules - update to 2.02-150.0.2
grub2-pc-modules - update to 2.02-150.0.2
grub2-efi-loongarch64 - update to 2.02-150.0.2
grub2 (Red Hat package) - addressed in versions 2.02-156.el8, 2.06-77.el9
grub2-efi-ia32-cdboot - update to 2.04-32
grub2-tools-efi - update to 2.04-32
grub2-efi-ia32 - update to 2.04-32
grub2-pc - update to 2.04-32
grub2-efi-x64 - update to 2.04-32
grub2-efi-x64-cdboot - update to 2.04-32
grub2 - update to 2.04-32
grub2-tools-minimal - update to 2.04-32
grub2-efi-aa64-cdboot - update to 2.04-32
grub2-tools - update to 2.04-32
grub2-efi-aa64 - update to 2.04-32
grub2-debugsource - update to 2.04-32
grub2-tools-extra - update to 2.04-32
grub2-debuginfo - update to 2.04-32
grub2-efi-x64-modules - update to 2.04-32
grub2-efi-ia32-modules - update to 2.04-32
grub2-help - update to 2.04-32
grub2-pc-modules - update to 2.04-32
grub2-efi-aa64-modules - update to 2.04-32
grub2-common - update to 2.04-32
OpenShift Service Mesh - update to 2.5.2
grub2 - update to 2.06-61

External References

Related Security Bulletins