First published: Fri Jan 12 2024(Updated: )
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Relax-and-recover Relax-and-recover | <=2.7 | |
SUSE Linux Enterprise | =15.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Fedoraproject Fedora | =39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.