PT-2021-7959 · Grub2+9 · Grub2+9

Marco Benatto

·

Published

2021-12-03

·

Updated

2024-09-05

·

CVE-2021-3981

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions grub2 versions 2.06 and earlier
Description A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set, allowing non-privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg.
Recommendations For grub2 versions 2.06 and earlier, as a temporary workaround, consider restricting access to the grub.cfg file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:2110
ALT-PU-2022-1151
ALT-PU-2022-1220
ALT-PU-2024-11222
AZL-34786
AZL-8937
BDU:2023-07627
CESA-2022_2110
CVE-2021-3981
OESA-2022-1597
OPENSUSE-SU-2024:11700-1
RHSA-2022:2110
RHSA-2022_2110
RLSA-2022:2110
USN-6355-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Grub2