CVE-2024-1048
published 2024-02-06CVE-2024-1048: A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.27%
18.7th percentile
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2024-49911 [MEDIUM] CWE-476 kernel: drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
kernel: drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
This commit adds a null check for the set_output_gamma function pointer
in the dcn20_set_output_transfer_func function. Previously,
set_output_gamma was being checked for null at line 1030, but then it
was being dereferenced without any null check at line 1048. This could
potentially lead to a null pointer dereference error if set_output_gamma
is null.
To fix this, we now ensure that set_output_gamma is not null before
dereferencing it. We do this by adding a null check for set_output_gamma
before the call to set_output_gamma at line 1048.
Pa
Red Hat
grub2: grub2-set-bootflag can be abused by local (pseudo-)users
vendor_redhat·2024-02-06·CVSS 5.9
CVE-2024-1048 [MEDIUM] CWE-459 grub2: grub2-set-bootflag can be abused by local (pseudo-)users
grub2: grub2-set-bootflag can be abused by local (pseudo-)users
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and m
Debian
CVE-2024-1048: grub2 - A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CV...
vendor_debian·2024·CVSS 5.9
CVE-2024-1048 [MEDIUM] CVE-2024-1048: grub2 - A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CV...
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-3qrv-r8v8-pmw7: A flaw was found in the grub2-set-bootflag utility of grub2
ghsa_unreviewed·2024-02-06·CVSS 5.9
CVE-2024-1048 [MEDIUM] CWE-459 GHSA-3qrv-r8v8-pmw7: A flaw was found in the grub2-set-bootflag utility of grub2
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:2456https://access.redhat.com/errata/RHSA-2024:3184https://access.redhat.com/security/cve/CVE-2024-1048https://bugzilla.redhat.com/show_bug.cgi?id=2256827https://www.openwall.com/lists/oss-security/2024/02/06/3http://www.openwall.com/lists/oss-security/2024/02/06/3https://access.redhat.com/errata/RHSA-2024:2456https://access.redhat.com/errata/RHSA-2024:3184https://access.redhat.com/security/cve/CVE-2024-1048https://bugzilla.redhat.com/show_bug.cgi?id=2256827https://lists.fedoraproject.org/archives/list/[email protected]/message/XRZQCVZ3XOASVFT6XLO7F2ZXOLOHIJZQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/https://security.netapp.com/advisory/ntap-20240223-0007/https://www.openwall.com/lists/oss-security/2024/02/06/3
2024-02-06
Published