Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Link | Tags |
---|---|
https://github.com/rear/rear/issues/3122 | issue tracking patch vendor advisory exploit |
https://github.com/rear/rear/pull/3123 | patch vendor advisory |
https://lists.debian.org/debian-lts-announce/2024/02/msg00003.html | mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JIN57LUPBI2GDJOK3PYXNHJTZT3AQTZ/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHKMPXJNXEJJE6EVYE5HM7EKEJFQMBN7/ | vendor advisory |