CVE-2024-1048
low-risk
Published 2024-02-06
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.
Do I need to act?
-
0.01% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.3/10
Low
LOCAL
/ LOW complexity
Affected Products (4)
Affected Vendors
References (14)
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-1048
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2256827
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-1048
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2256827
23
/ 100
low-risk
Severity
13/34 · Low
Exploitability
0/34 · Minimal
Exposure
10/34 · Low