PT-2022-12908 · Grub2 · Grub2

Ludwig Nussel

·

Published

2022-03-16

·

Updated

2024-07-31

·

CVE-2021-46705

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions grub2 versions prior to 2.06-150400.7.1 grub2 versions prior to 2.06-18.1
Description A local attacker can exploit an Insecure Temporary File vulnerability in grub-once of grub2 to truncate arbitrary files.
Recommendations For SUSE Linux Enterprise Server 15 SP4, update to a version after 2.06-150400.7.1. For SUSE openSUSE Factory, update to a version after 2.06-18.1.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-46705
OPENSUSE-SU-2024:11926-1
ROSA-SA-2024-2461

Affected Products

Grub2