{"id":24348,"date":"2022-05-12T00:28:21","date_gmt":"2022-05-11T20:28:21","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167090\/RHSA-2022-2110-01.txt"},"modified":"2022-05-15T09:38:51","modified_gmt":"2022-05-15T05:08:51","slug":"red-hat-security-advisory-2022-2110-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-2110-01\/","title":{"rendered":"Red Hat Security Advisory 2022-2110-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Low: grub2 security, bug fix, and enhancement update<br \/>\nAdvisory ID: RHSA-2022:2110-01<br \/>\nProduct: Red Hat Enterprise Linux<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:2110<br \/>\nIssue date: 2022-05-10<br \/>\nCVE Names: CVE-2021-3981<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">An update for grub2 is now available for Red Hat Enterprise Linux 8.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Low. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Relevant releases\/architectures:<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux BaseOS (v. 8) &#8211; aarch64, noarch, ppc64le, x86_64<\/p>\n<p dir=\"ltr\">3. Description:<\/p>\n<p dir=\"ltr\">The grub2 packages provide version 2 of the Grand Unified Boot Loader<br \/>\n(GRUB), a highly configurable and customizable boot loader with modular<br \/>\narchitecture. The packages support a variety of kernel formats, file<br \/>\nsystems, computer architectures, and hardware devices.<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* grub2: Incorrect permission in grub.cfg allow unprivileged user to read<br \/>\nthe file content (CVE-2021-3981)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p dir=\"ltr\">Additional Changes:<\/p>\n<p dir=\"ltr\">For detailed information on changes in this release, see the Red Hat<br \/>\nEnterprise Linux 8.6 Release Notes linked from the References section.<\/p>\n<p dir=\"ltr\">4. Solution:<\/p>\n<p dir=\"ltr\">For details on how to apply this update, which includes the changes<br \/>\ndescribed in this advisory, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">5. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1809246 &#8211; [RFE] GRUB does not consider information from proxy dhcp server<br \/>\n1899903 &#8211; grub2-mkconfig is never run on kernel upgrade even if GRUB_ENABLE_BLSCFG=false<br \/>\n1914575 &#8211; grub-boot-success.service should not be started inside systemd-nspawn container<br \/>\n2016269 &#8211; RPM grub2-tools-minimal is shipping prelink config files although prelink is absent in rhel8<br \/>\n2020927 &#8211; GRUB_TERMINAL_INPUT=at_keyboard makes grub stay on boot menu instead of starting the timeout<br \/>\n2024170 &#8211; CVE-2021-3981 grub2: Incorrect permission in grub.cfg allow unprivileged user to read the file content<br \/>\n2048904 &#8211; Cannot EFI chainload onto local disk when EFI partition is in Software Raid<br \/>\n2061252 &#8211; grub on OpenFirmware : search &#8211;hint-ieee1275= does not work<br \/>\n2069157 &#8211; grub2 signed by Red Hat Test Certificate<\/p>\n<p dir=\"ltr\">6. Package List:<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux BaseOS (v. 8):<\/p>\n<p dir=\"ltr\">Source:<br \/>\ngrub2-2.02-123.el8.src.rpm<\/p>\n<p dir=\"ltr\">aarch64:<br \/>\ngrub2-debuginfo-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-debugsource-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-efi-aa64-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-efi-aa64-cdboot-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-tools-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-tools-debuginfo-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-tools-extra-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-tools-extra-debuginfo-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-tools-minimal-2.02-123.el8.aarch64.rpm<br \/>\ngrub2-tools-minimal-debuginfo-2.02-123.el8.aarch64.rpm<\/p>\n<p dir=\"ltr\">noarch:<br \/>\ngrub2-common-2.02-123.el8.noarch.rpm<br \/>\ngrub2-efi-aa64-modules-2.02-123.el8.noarch.rpm<br \/>\ngrub2-efi-ia32-modules-2.02-123.el8.noarch.rpm<br \/>\ngrub2-efi-x64-modules-2.02-123.el8.noarch.rpm<br \/>\ngrub2-pc-modules-2.02-123.el8.noarch.rpm<br \/>\ngrub2-ppc64le-modules-2.02-123.el8.noarch.rpm<\/p>\n<p dir=\"ltr\">ppc64le:<br \/>\ngrub2-debuginfo-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-debugsource-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-ppc64le-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-tools-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-tools-debuginfo-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-tools-extra-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-tools-extra-debuginfo-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-tools-minimal-2.02-123.el8.ppc64le.rpm<br \/>\ngrub2-tools-minimal-debuginfo-2.02-123.el8.ppc64le.rpm<\/p>\n<p dir=\"ltr\">x86_64:<br \/>\ngrub2-debuginfo-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-debugsource-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-efi-ia32-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-efi-ia32-cdboot-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-efi-x64-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-efi-x64-cdboot-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-pc-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-debuginfo-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-efi-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-efi-debuginfo-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-extra-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-extra-debuginfo-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-minimal-2.02-123.el8.x86_64.rpm<br \/>\ngrub2-tools-minimal-debuginfo-2.02-123.el8.x86_64.rpm<\/p>\n<p dir=\"ltr\">These packages are GPG signed by Red Hat for security. Our key and<br \/>\ndetails on how to verify the signature are available from<br \/>\nhttps:\/\/access.redhat.com\/security\/team\/key\/<\/p>\n<p dir=\"ltr\">7. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2021-3981<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#low<br \/>\nhttps:\/\/access.redhat.com\/documentation\/en-us\/red_hat_enterprise_linux\/8\/html\/8.6_release_notes\/<\/p>\n<p dir=\"ltr\">8. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYnqRstzjgjWX9erEAQgbGA\/\/Yt1p6YQS2BSVdTiseVPgoc+JJui5N5wn<br \/>\n\/YkZy6vGvKSdtaYNegyb4arqW8+qIbLrlNF5j1p16nrZ2a+ONRFxozO866M1FIXa<br \/>\nLc6edJKULuW20398JD7Txu4mYnTZO692HLHSYvTsadS6wF+oXm1NqoTnaQBJM6F+<br \/>\nMiTxXE6iOb247LTNElA2Zqq+0qGR4EJ84DNmF82Y4OVmcawCpCmVQFPNXRasfhNl<br \/>\nEqKuhGvt3vRCW5VY51b6nwC5b+AiAClFkIIlkfaurqgZzPInnX0fZyrO41Jy81So<br \/>\nECK+ZZlOpZDhh8r6XnjPVvzVHwY8iG3LvAPvG3UWqwcXViRUheajdL2LhJyPjg9j<br \/>\nsf2Q+eVrf9WfKGWdPHsw1+bu08ebHkKdAth6psW7QuUuCjj4AW+X2amm0jE\/eFUi<br \/>\nSLiSfh3V7rhpLWaPg+S4ptTyuAswpkXR2smMBmljojfx3wGvJVelO+183asFHR4B<br \/>\n+aXSxw05jkiwNZB+7TMdhNiiKkC7TagxeQcMqMqD+yvk8mOeTBNafG7WzbyLO8io<br \/>\nHFn8VrzXWc3RHJcyMT3oeR6bBVM3ro1mm8BOiikK1nFwNJtkT0ct+Yj9glwUXmGy<br \/>\nEAQempaqwkyyrYtmrIdDu2pp07bO2\/LHHloDm4JF3V8bHfWlHc\/IPEP6QiibSx5P<br \/>\nQ+YUwE3ShUs=<br \/>\n=ZVXv<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Low: grub2 security, bug fix, and enhancement update Advisory ID: RHSA-2022:2110-01 Product: Red Hat Enterprise Linux Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:2110 Issue date: 2022-05-10 CVE Names: CVE-2021-3981 ===================================================================== 1. Summary: An update for grub2 is now available for Red Hat Enterprise Linux 8. Red Hat &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-24348","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/24348","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=24348"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/24348\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=24348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=24348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=24348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}