5.9

CVE-2019-14865

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnuGrub2 Version-
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Eus Version8.1
   RedhatEnterprise Linux Eus Version8.2
   RedhatEnterprise Linux Eus Version8.4
   RedhatEnterprise Linux Eus Version8.6
   RedhatEnterprise Linux Eus Version8.8
   RedhatEnterprise Linux Server Aus Version8.2
   RedhatEnterprise Linux Server Aus Version8.4
   RedhatEnterprise Linux Server Aus Version8.6
   RedhatEnterprise Linux Server Tus Version8.2
   RedhatEnterprise Linux Server Tus Version8.4
   RedhatEnterprise Linux Server Tus Version8.6
   RedhatEnterprise Linux Server Tus Version8.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 1.5 4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
secalert@redhat.com 5.9 1.5 4
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
CWE-267 Privilege Defined With Unsafe Actions

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.