CVE-2019-14865: Medium severity centos grub2-pc-modules vulnerability
A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
Other sources
A flaw was found in the grub2-set-bootflag utility of grub2. When the utility is run under resource pressure (by setting RLIMIT), it can cause grub2 config files to be truncated leaving the system non-bootable on subsequent reboots.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14865?
CVE-2019-14865 is a vulnerability found in the grub2-set-bootflag utility of grub2.
How can a local attacker exploit CVE-2019-14865?
A local attacker could run the grub2-set-bootflag utility under resource pressure, causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.
Which software is affected by CVE-2019-14865?
Grub2 is affected by CVE-2019-14865.
What is the severity of CVE-2019-14865?
CVE-2019-14865 has a severity rating of 5.5, which is considered medium.
How can I fix CVE-2019-14865?
Currently, there is no known fix for CVE-2019-14865. It is recommended to apply any patches or updates provided by the vendor.