安全公告详情

NS-SA-2024-0068

2024-09-03 09:35:08

简介

important: grub2 security update

严重级别

important

主题

An update for grub2 is now available for NewStart CGSL MAIN 6.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

grub2:


Security Fix(es):
grub2: A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg.(CVE-2021-3981)
grub2: A flaw was found in grub2 when handling IPv4 packets. This flaw allows an attacker to craft a malicious packet, triggering an integer underflow in grub code. Consequently, the memory allocation for handling the packet data may be smaller than the size needed. This issue causes an out-of-bands write during packet handling, compromising data integrity, confidentiality issues, a denial of service, and remote code execution.(CVE-2022-28733)
grub2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.02.F2B12.

影响组件

  • grub2

影响产品

  • CGSL MAIN 6.02

更新包

{"fix":[{"product":"CGSL MAIN 6.02","pkgs":[{"binary":["grub2-tools-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.x86_64.rpm","grub2-efi-x64-modules-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.noarch.rpm","grub2-common-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.noarch.rpm","grub2-efi-x64-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.x86_64.rpm","grub2-tools-extra-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.x86_64.rpm","grub2-pc-modules-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.noarch.rpm","grub2-tools-minimal-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.x86_64.rpm","grub2-tools-efi-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.x86_64.rpm","grub2-pc-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.x86_64.rpm"],"source":"grub2-2.02-90.el8_3.1.cgslv6_2.14.g52ff5f0a.src.rpm"}]}]}

CVE

参考