REDHAT-BUG-2258396: Medium severity Relax-and-Recover ReaR vulnerability
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUBRESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
https://github.com/rear/rear/issues/3122 https://github.com/rear/rear/pull/3123
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2258396?
The severity of REDHAT-BUG-2258396 is considered high due to the exposure of sensitive information to local attackers.
How do I fix REDHAT-BUG-2258396?
To fix REDHAT-BUG-2258396, update Relax-and-Recover to the latest version that addresses this vulnerability.
Who is affected by REDHAT-BUG-2258396?
Users of Relax-and-Recover ReaR version 2.7 are affected by REDHAT-BUG-2258396.
What impact does REDHAT-BUG-2258396 have on systems?
REDHAT-BUG-2258396 allows local attackers to read system secrets, potentially leading to unauthorized access or privilege escalation.
Is there a workaround for REDHAT-BUG-2258396?
Currently, the best workaround for REDHAT-BUG-2258396 is to avoid using the GRUB_RESCUE=y option until a patch is applied.