Privilege Defined With Unsafe Actions in grub - CVE-2019-14865

 

Privilege Defined With Unsafe Actions in grub - CVE-2019-14865

Published: September 10, 2024


Vulnerability identifier: #VU97100
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-14865
CWE-ID: CWE-267
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
grub
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Juniper Secure Analytics (JSA)
grub2 (Red Hat package)
grub2
grub2-tools
grub2-efi-aa64-cdboot
grub2-tools-extra
grub2-tools-minimal
grub2-efi-ia32
grub2-efi-ia32-cdboot
grub2-efi-x64
grub2-efi-x64-cdboot
grub2-pc
grub2-tools-efi
grub2-common
grub2-efi-aa64-modules
grub2-efi-ia32-modules
grub2-efi-x64-modules
grub2-pc-modules
grub2-efi-loongarch64
grub2-efi-loongarch64-cdboot
grub2-efi-aa64
grub2-help
grub2-debugsource
grub2-debuginfo

Detailed vulnerability description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in the grub2-set-bootflag utility. A local user can run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.


How to mitigate CVE-2019-14865

Install updates from vendor's website.

Sources