Bug 1219669 (CVE-2024-1048) - VUL-0: CVE-2024-1048: grub2,trustedgrub2: grub2-set-bootflag can be abused by local (pseudo-)users
Summary: VUL-0: CVE-2024-1048: grub2,trustedgrub2: grub2-set-bootflag can be abused by...
Status: RESOLVED FIXED
Alias: CVE-2024-1048
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/393250/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-1048:3.3:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-07 09:43 UTC by SMASH SMASH
Modified: 2024-02-07 09:44 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-02-07 09:43:11 UTC
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1048
https://seclists.org/oss-sec/2024/q1/112
https://bugzilla.redhat.com/show_bug.cgi?id=2256827
https://access.redhat.com/security/cve/CVE-2024-1048
http://www.openwall.com/lists/oss-security/2024/02/06/3
https://www.cve.org/CVERecord?id=CVE-2024-1048
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14865
https://bugzilla.redhat.com/show_bug.cgi?id=2256678
Comment 1 Andrea Mattiazzo 2024-02-07 09:44:04 UTC
Closed since all code stream are not affected.
Comment 2 Andrea Mattiazzo 2024-02-07 09:44:50 UTC
(In reply to Andrea Mattiazzo from comment #1)
> Closed since all code stream are not affected.