CVE-2024-1048

A

flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:grub2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

History

21 Nov 2024, 08:49

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/06/3 -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/XRZQCVZ3XOASVFT6XLO7F2ZXOLOHIJZQ/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/ -
  • () https://security.netapp.com/advisory/ntap-20240223-0007/ -
References () https://access.redhat.com/errata/RHSA-2024:2456 - () https://access.redhat.com/errata/RHSA-2024:2456 -
References () https://access.redhat.com/errata/RHSA-2024:3184 - () https://access.redhat.com/errata/RHSA-2024:3184 -
References () https://access.redhat.com/security/cve/CVE-2024-1048 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2024-1048 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2256827 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2256827 - Issue Tracking, Vendor Advisory
References () https://www.openwall.com/lists/oss-security/2024/02/06/3 - Mailing List, Third Party Advisory () https://www.openwall.com/lists/oss-security/2024/02/06/3 - Mailing List, Third Party Advisory

16 Sep 2024, 16:15

Type Values Removed Values Added
References
  • {'url': 'http://www.openwall.com/lists/oss-security/2024/02/06/3', 'tags': ['Mailing List', 'Third Party Advisory'], 'source': '[email protected]'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/[email protected]/message/XRZQCVZ3XOASVFT6XLO7F2ZXOLOHIJZQ/', 'source': '[email protected]'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/[email protected]/message/YSJAEGRR3XHMBBBKYOVMII4P34IXEYPE/', 'source': '[email protected]'}
  • {'url': 'https://security.netapp.com/advisory/ntap-20240223-0007/', 'source': '[email protected]'}

22 May 2024, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3184 -

30 Apr 2024, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2456 -

Information

Published : 2024-02-06 18:15

Updated : 2024-11-21 08:49


NVD link : CVE-2024-1048

Mitre link : CVE-2024-1048

CVE.ORG link : CVE-2024-1048


JSON object : View

CWE
CWE-459

Incomplete Cleanup