RHSA-2024:2002: Moderate: grub2 security update
Moderate: grub2 security update
Other sources
The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.<br>Security Fix(es):<br><li> grub2: Buffer overflow in grubfontconstructglyph() can lead to out-of-bound write and possible secure boot bypass (CVE-2022-2601)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2002?
RHSA-2024:2002 is classified as a moderate severity vulnerability.
What products are affected by RHSA-2024:2002?
RHSA-2024:2002 affects several Red Hat Enterprise Linux products including Desktop, Server, and Workstation editions.
How do I fix RHSA-2024:2002?
To fix RHSA-2024:2002, update the grub2 package to version 2.02-0.87.el7_9.14 or higher.
What vulnerabilities does RHSA-2024:2002 address?
RHSA-2024:2002 addresses a security vulnerability in the grub2 bootloader used in affected Red Hat systems.
Is it safe to ignore the update for RHSA-2024:2002?
It is not safe to ignore the update for RHSA-2024:2002, as it could leave your system vulnerable to exploitation.