CVE-2021-46705: grub2-once uses fixed file name in /var/tmp
A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-46705.
What is the title of the vulnerability?
The title of the vulnerability is 'A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4'.
What is the affected software?
The affected software includes SUSE Linux Enterprise Server 15 SP4 with grub2 versions prior to 2.06-150400.7.1, and openSUSE Factory with grub2 versions prior to 2.06-18.1.
What is the severity of CVE-2021-46705?
The severity of CVE-2021-46705 is medium with a CVSS score of 4.4.
How can I fix this vulnerability?
To fix this vulnerability, update SUSE Linux Enterprise Server 15 SP4 to grub2 version 2.06-150400.7.1 or later, and update openSUSE Factory to grub2 version 2.06-18.1 or later.