https://seclists.org/oss-sec/2024/q1/112: CVE-2024-1048: grub2-set-bootflag may be abused to fill up /boot, bypass RLIMIT_NPROC
Published Feb 6, 2024
·Updated
Affected Software
3 affected components
Red Hat grub2-set-bootflag
Fedora grub2-set-bootflag
Rocky Linux grub2-set-bootflag
Frequently Asked Questions
1
What is the severity of CVE-2024-1048?
CVE-2024-1048 has a high severity due to its potential to abuse the grub2-set-bootflag utility to fill up the /boot directory.
2
How does CVE-2024-1048 affect SUID root programs?
CVE-2024-1048 exploits the SUID root permissions of grub2-set-bootflag, allowing users to bypass RLIMIT_NPROC.
3
Which systems are impacted by CVE-2024-1048?
CVE-2024-1048 affects Red Hat, Fedora, and Rocky Linux implementations of grub2-set-bootflag.
4
How do I fix CVE-2024-1048?
To fix CVE-2024-1048, update the grub2-set-bootflag package to the latest patched version provided by your distribution.
5
What vulnerability does CVE-2024-1048 expose in grub2-set-bootflag?
CVE-2024-1048 exposes a vulnerability that allows unauthorized users to fill up the /boot directory and bypass resource limits.