SB2019112643 - Fedora 31 update for grub2



SB2019112643 - Fedora 31 update for grub2

Published: November 26, 2019 Updated: April 25, 2025

Security Bulletin ID SB2019112643
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege Defined With Unsafe Actions (CVE-ID: CVE-2019-14865)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in the grub2-set-bootflag utility. A local user can run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.


Remediation

Install update from vendor's website.