Privilege Defined With Unsafe Actions in grub - CVE-2019-14865
Published: September 10, 2024
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the grub2-set-bootflag utility. A local user can run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Juniper Secure Analytics (JSA)
grub2 (Red Hat package)
grub2
grub2-tools
grub2-efi-aa64-cdboot
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-loongarch64
grub2-efi-loongarch64-cdboot
grub2-efi-aa64
grub2-help
grub2-debugsource
grub2-debuginfo
How to mitigate CVE-2019-14865
grub2 (Red Hat package) - update to 2.02-78.el8_1.1
grub2 - addressed in versions 2.02-85.fc30, 2.02-86.fc30, 2.02-87.fc30, 2.02-102.fc31, 2.02-103.fc31
grub2-tools - update to 2.02-150.0.2
grub2-efi-aa64-cdboot - update to 2.02-150.0.2
grub2-tools-extra - update to 2.02-150.0.2
grub2-tools-minimal - update to 2.02-150.0.2
grub2-efi-ia32 - update to 2.02-150.0.2
grub2-efi-ia32-cdboot - update to 2.02-150.0.2
grub2-efi-x64 - update to 2.02-150.0.2
grub2-efi-x64-cdboot - update to 2.02-150.0.2
grub2-pc - update to 2.02-150.0.2
grub2-tools-efi - update to 2.02-150.0.2
grub2-common - update to 2.02-150.0.2
grub2-efi-aa64-modules - update to 2.02-150.0.2
grub2-efi-ia32-modules - update to 2.02-150.0.2
grub2-efi-x64-modules - update to 2.02-150.0.2
grub2-pc-modules - update to 2.02-150.0.2
grub2-efi-loongarch64 - update to 2.02-150.0.2
grub2-efi-loongarch64-cdboot - update to 2.02-150.0.2
grub2-efi-aa64 - update to 2.02-150.0.2
grub2-help - update to 2.04-32
grub2 - update to 2.04-32
grub2-tools-minimal - update to 2.04-32
grub2-efi-aa64-cdboot - update to 2.04-32
grub2-tools - update to 2.04-32
grub2-efi-aa64 - update to 2.04-32
grub2-debugsource - update to 2.04-32
grub2-tools-extra - update to 2.04-32
grub2-debuginfo - update to 2.04-32
grub2-efi-x64-modules - update to 2.04-32
grub2-efi-ia32-modules - update to 2.04-32
grub2-pc-modules - update to 2.04-32
grub2-efi-aa64-modules - update to 2.04-32
grub2-common - update to 2.04-32
grub2-efi-x64-cdboot - update to 2.04-32
grub2-efi-ia32-cdboot - update to 2.04-32
grub2-efi-x64 - update to 2.04-32
grub2-pc - update to 2.04-32
grub2-efi-ia32 - update to 2.04-32
grub2-tools-efi - update to 2.04-32
grub2 - update to 2.06-61
External References
Related Security Bulletins
- Denial of service in grub
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Amazon Linux AMI update for grub2
- openEuler update for grub2
- Anolis OS update for grub2
- Red Hat Enterprise Linux 8 update for grub2
- Fedora 31 update for grub2
- Fedora 30 update for grub2
- Fedora 31 update for grub2
- Fedora 30 update for grub2
- Fedora 30 update for grub2