First published: Wed Feb 23 2022(Updated: )
A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Gnu Grub2 | <2.06-150400.7.1 | |
SUSE Linux Enterprise Server | =15-sp4 | |
Gnu Grub2 | <2.06-18.1 | |
openSUSE Factory |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-46705.
The title of the vulnerability is 'A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4'.
The affected software includes SUSE Linux Enterprise Server 15 SP4 with grub2 versions prior to 2.06-150400.7.1, and openSUSE Factory with grub2 versions prior to 2.06-18.1.
The severity of CVE-2021-46705 is medium with a CVSS score of 4.4.
To fix this vulnerability, update SUSE Linux Enterprise Server 15 SP4 to grub2 version 2.06-150400.7.1 or later, and update openSUSE Factory to grub2 version 2.06-18.1 or later.