CVE-2019-14865

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
gnugrub2
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
grub2
bookworm
2.06-13+deb12u1
fixed
bookworm (security)
2.06-13+deb12u1
fixed
bullseye
2.06-3~deb11u6
fixed
bullseye (security)
2.06-3~deb11u6
fixed
sid
2.12-5
fixed
trixie
2.12-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grub2
bionic
not-affected
disco
not-affected
eoan
not-affected
trusty
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grub2-common
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-aa64
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-aa64-cdboot
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-aa64-modules
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-ia32
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-ia32-cdboot
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-ia32-modules
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-x64
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-x64-cdboot
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-efi-x64-modules
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-pc
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-pc-modules
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-ppc64le
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-ppc64le-modules
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-tools
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-tools-efi
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-tools-extra
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed
grub2-tools-minimal
RHEL 8
1:2.02-78.el8_1.1
fixed
RHEL 8.1 E4S
1:2.02-78.el8_1.1
fixed
RHEL 8.1 EUS
1:2.02-78.el8_1.1
fixed