CVE-2024-1048

EUVD-2024-16824
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
gnugrub2
-
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
grub2
bookworm
2.06-13+deb12u1
fixed
bookworm (security)
2.06-13+deb12u1
fixed
bullseye
2.06-3~deb11u6
fixed
bullseye (security)
2.06-3~deb11u6
fixed
forky
2.14~git20250718.0e36779-2
fixed
sid
2.14~git20250718.0e36779-2
fixed
trixie
2.12-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grub2
bionic
not-affected
focal
not-affected
jammy
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
not-affected
xenial
not-affected
grub2-unsigned
bionic
not-affected
focal
not-affected
jammy
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
ignored
xenial
not-affected
grub2-signed
bionic
not-affected
focal
not-affected
jammy
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
trusty
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grub2-common
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-efi-aa64
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-efi-aa64-cdboot
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-efi-aa64-modules
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-efi-ia32
RHEL 8
1:2.02-156.el8
fixed
grub2-efi-ia32-cdboot
RHEL 8
1:2.02-156.el8
fixed
grub2-efi-ia32-modules
RHEL 8
1:2.02-156.el8
fixed
grub2-efi-x64
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-efi-x64-cdboot
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-efi-x64-modules
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-pc
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-pc-modules
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-ppc64le
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-ppc64le-modules
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-tools
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-tools-efi
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-tools-extra
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed
grub2-tools-minimal
RHEL 8
1:2.02-156.el8
fixed
RHEL 9
1:2.06-77.el9
fixed