CVE-2024-23301
published 2024-01-12CVE-2024-23301: Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets…
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.29%
21.0th percentile
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rear | < rear 2.7+dfsg-1+deb12u1 (bookworm) | rear 2.7+dfsg-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| relax-and-recover | relax-and-recover | <= 2.7 | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rear: creates a world-readable initrd
vendor_redhat·2024-01-13·CVSS 5.5
CVE-2024-23301 [MEDIUM] CWE-359 rear: creates a world-readable initrd
rear: creates a world-readable initrd
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
A vulnerability has been identified in Relax-and-Recover (ReaR), where the use of GRUB_RESCUE=y results in the creation of an initrd that is readable by anyone. This flaw could potentially enable local attackers to obtain access to system secrets that are typically restricted to root privileges.
Statement: A moderate security concern has been identified in Relax-and-Recover (ReaR), particularly when the non-default configuration GRUB_RESCUE=y is used within Red Hat Enterprise Linux (RHEL). This setting results in the creation of a world-readable initrd, potent
Debian
CVE-2024-23301: rear - Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when us...
vendor_debian·2024·CVSS 5.5
CVE-2024-23301 [MEDIUM] CVE-2024-23301: rear - Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when us...
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Scope: local
bookworm: resolved (fixed in 2.7+dfsg-1+deb12u1)
bullseye: resolved (fixed in 2.6+dfsg-1+deb11u1)
forky: resolved (fixed in 2.7+dfsg-1.2)
sid: resolved (fixed in 2.7+dfsg-1.2)
trixie: resolved (fixed in 2.7+dfsg-1.2)
GHSA
GHSA-5g36-x562-44f9: Relax-and-Recover (aka ReaR) through 2
ghsa_unreviewed·2024-01-13
CVE-2024-23301 [MEDIUM] CWE-276 GHSA-5g36-x562-44f9: Relax-and-Recover (aka ReaR) through 2
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
OSV
CVE-2024-23301: Relax-and-Recover (aka ReaR) through 2
osv·2024-01-12·CVSS 5.5
CVE-2024-23301 [MEDIUM] CVE-2024-23301: Relax-and-Recover (aka ReaR) through 2
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/rear/rear/issues/3122https://github.com/rear/rear/pull/3123https://lists.debian.org/debian-lts-announce/2024/02/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JIN57LUPBI2GDJOK3PYXNHJTZT3AQTZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHKMPXJNXEJJE6EVYE5HM7EKEJFQMBN7/https://github.com/rear/rear/issues/3122https://github.com/rear/rear/pull/3123https://lists.debian.org/debian-lts-announce/2024/02/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2025/12/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JIN57LUPBI2GDJOK3PYXNHJTZT3AQTZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHKMPXJNXEJJE6EVYE5HM7EKEJFQMBN7/https://lists.fedoraproject.org/archives/list/[email protected]/message/7JIN57LUPBI2GDJOK3PYXNHJTZT3AQTZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UHKMPXJNXEJJE6EVYE5HM7EKEJFQMBN7/
2024-01-12
Published