CVE-2024-1048

Updated: 2024-11-24 05:38:02.381286

Description:

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x LOW 3.3000000000000003

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU grub2 2.06 3.3 LOW Released CLSA-2025:1742805183 2025-03-25 03:31:33
CentOS 7 ELS grub2 2.02 3.3 LOW Ignored 2024-02-14 08:26:36
CentOS 8.4 ELS grub2 2.02 3.3 LOW Released CLSA-2025:1744222859 2025-04-10 03:19:17
CentOS 8.5 ELS grub2 2.02 3.3 LOW Released CLSA-2025:1744628858 2025-04-15 04:07:59
CentOS Stream 8 ELS grub2 2.02 3.3 LOW Released CLSA-2024:1724266264 2024-08-21 17:38:42
CloudLinux 7 ELS grub2 2.02 3.3 LOW Ignored 2024-07-22 12:05:51
Oracle Linux 7 ELS grub2 2.02 3.3 LOW Ignored 2024-12-03 12:09:58
RHEL 7 ELS grub2 2.02 3.3 LOW Ignored 2025-05-13 04:16:22