REDHAT-BUG-2024170: Low severity centos grub2-pc-modules vulnerability
GRUB2 grub.cfg configuration file is created with the wrong permission (0644) allowing unprivileged users to read grub's configuration file content. This presents a low Confidentiality risk as grub.cfg may contain encrypted passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2024170?
The severity of REDHAT-BUG-2024170 is considered low due to its limited impact on confidentiality.
How do I fix REDHAT-BUG-2024170?
To fix REDHAT-BUG-2024170, ensure that the grub.cfg configuration file has the appropriate permissions set to restrict access.
Who is affected by REDHAT-BUG-2024170?
Users of GNU GRUB2 with the incorrect permission settings on grub.cfg are affected by REDHAT-BUG-2024170.
What is the main risk associated with REDHAT-BUG-2024170?
The main risk associated with REDHAT-BUG-2024170 is the potential exposure of sensitive information in the grub.cfg file.
Is REDHAT-BUG-2024170 a known issue?
Yes, REDHAT-BUG-2024170 is a known issue reported in the Red Hat Bugzilla system.